MEDIUM
Possible privilege escalation through prctl() and suid_dumpable
Published Jul 7, 2006
4.6
MEDIUMCVSS 2.0
EPSS 4.39%
Description
The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a local user to cause a denial of service (disk consumption) and possibly gain privileges via the PR_SET_DUMPABLE argument of the prctl function and a program that causes a core dump file to be created in a directory for which the user does not have permissions.
Affected products
No data.
OR
- 2.6.13
- 2.6.13.1
- 2.6.13.2
- 2.6.13.3
- 2.6.13.4
- 2.6.13.5
- 2.6.14
- 2.6.14
- 2.6.14
- 2.6.14
- 2.6.14
- 2.6.14
- 2.6.14.1
- 2.6.14.2
- 2.6.14.3
- 2.6.14.4
- 2.6.14.5
- 2.6.14.6
- 2.6.14.7
- 2.6.15
- 2.6.15
- 2.6.15
- 2.6.15
- 2.6.15
- 2.6.15
- 2.6.15
- 2.6.15
- 2.6.15.1
- 2.6.15.2
- 2.6.15.3
- 2.6.15.4
- 2.6.15.5
- 2.6.15.6
- 2.6.15.7
- 2.6.16
- 2.6.16
- 2.6.16
- 2.6.16
- 2.6.16
- 2.6.16
- 2.6.16
- 2.6.16.1
- 2.6.16.2
- 2.6.16.3
- 2.6.16.4
- 2.6.16.5
- 2.6.16.6
- 2.6.16.7
- 2.6.16.8
- 2.6.16.9
- 2.6.16.10
- 2.6.16.11
- 2.6.16.12
- 2.6.16.13
- 2.6.16.14
- 2.6.16.15
- 2.6.16.16
- 2.6.16.17
- 2.6.16.18
- 2.6.16.19
- 2.6.16.20
- 2.6.16.21
- 2.6.16.22
- 2.6.16.23
- 2.6.17
- 2.6.17
- 2.6.17
- 2.6.17
- 2.6.17
- 2.6.17
- 2.6.17
- 2.6.17.1
- 2.6.17.2
- 2.6.17.3
No data.
Red Hat Enterprise Linux 4
kernel-0:2.6.9-34.0.2.EL
Fixed · RHSA-2006:0574
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | kernel-0:2.6.9-34.0.2.EL | Fixed | RHSA-2006:0574 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (38)
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=195902 x_refsource_MISC
- http://secunia.com/advisories/20953 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/20960 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/20965 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/20986 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/20991 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21179 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21498 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21966 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securitytracker.com/id?1016451 vdb-entryx_refsource_SECTRACK
- http://support.avaya.com/elmodocs2/security/ASA-2006-162.htm x_refsource_CONFIRM
- http://www.kernel.org/git/?p=linux/kernel/git/stable/linux-2.6.17.y.git%3Ba=commit%3Bh=0af184bb9f80edfbb94de46cb52e9592e5a547b0 x_refsource_CONFIRM
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.24 x_refsource_CONFIRM
- http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.17.4 x_refsource_CONFIRM
- http://www.novell.com/linux/security/advisories/2006_16_sr.html vendor-advisoryx_refsource_SUSE
- http://www.novell.com/linux/security/advisories/2006_17_sr.html vendor-advisoryx_refsource_SUSE
- http://www.novell.com/linux/security/advisories/2006_42_kernel.html vendor-advisoryx_refsource_SUSE
- http://www.novell.com/linux/security/advisories/2006_47_kernel.html vendor-advisoryx_refsource_SUSE
- http://www.novell.com/linux/security/advisories/2006_49_kernel.html vendor-advisoryx_refsource_SUSE
- http://www.osvdb.org/27030 vdb-entryx_refsource_OSVDB
- http://www.redhat.com/support/errata/RHSA-2006-0574.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/439483/100/100/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/439610/100/100/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/439869/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/440057/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/440117/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/440118/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/440379/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/18874 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/usn-311-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2006/2699 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2006-2451 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=195902 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-2452 Advisory
- https://issues.rpath.com/browse/RPL-488 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2006-2451
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11336 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2006-2451
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 7, 2006
Updated Aug 7, 2024
Reserved May 18, 2006
Link CVE-2006-2451
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2006-2452 Assigner redhat
Published Jul 7, 2006
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2006-2452