arts: does not check the return value of the setuid which prevents artsd from dropping privileges
Published Jun 15, 2006
7.8
HIGHCVSS 3.1
EPSS 0.39%
Description
artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges.
Affected products
Remediation
Red Hat statement
Not vulnerable. We do not ship aRts as setuid root on Red Hat Enterprise Linux 2.1, 3, or 4.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:L/AC:H/Au:S/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.39% (0.00385) | 30.17th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.39% (0.00385) | 30.03th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.11% (0.00107) | 26.45th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.06% (0.00059) | 27.15th | v3 (v2023.03.01) |
| Jun 12, 2024 | 0.06% (0.00059) | 25.18th | v3 (v2023.03.01) |
| Jan 21, 2024 | 0.06% (0.00059) | 23.15th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.06% (0.00063) | 25.50th | v3 (v2023.03.01) |
| Aug 11, 2023 | 0.09% (0.00091) | 37.85th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00044) | 8.24th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.55% (0.01547) | 74.94th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.55% (0.01547) | 72.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.55% (0.01547) | 51.82th | v2 (v2022.01.01) |
References (28)
- http://dot.kde.org/1150310128/ x_refsource_CONFIRMNot Applicable
- http://mail.gnome.org/archives/beast/2006-December/msg00025.html mailing-listx_refsource_MLISTMailing List
- http://secunia.com/advisories/20677 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/20786 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/20827 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/20868 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/20899 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/25032 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/25059 third-party-advisoryx_refsource_SECUNIABroken Link
- http://security.gentoo.org/glsa/glsa-200704-22.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://securitytracker.com/id?1016298 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.468256 vendor-advisoryx_refsource_SLACKWAREMailing ListThird Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200606-22.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://www.kde.org/info/security/advisory-20060614-2.txt x_refsource_CONFIRMPatchVendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:107 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.novell.com/linux/security/advisories/2006_38_security.html vendor-advisoryx_refsource_SUSEBroken Link
- http://www.osvdb.org/26506 vdb-entryx_refsource_OSVDBBroken Link
- http://www.securityfocus.com/archive/1/437362/100/0/threaded mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/18429 vdb-entryx_refsource_BIDBroken LinkPatchThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/23697 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.vupen.com/english/advisories/2006/2357 vdb-entryx_refsource_VUPENBroken Link
- http://www.vupen.com/english/advisories/2007/0409 vdb-entryx_refsource_VUPENBroken Link
- https://access.redhat.com/security/cve/CVE-2006-2916 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2259536 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27221 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://mail.gnome.org/archives/beast/2006-December/msg00025.html
- https://nvd.nist.gov/vuln/detail/CVE-2006-2916
- https://www.cve.org/CVERecord?id=CVE-2006-2916
Change history (0)
No recorded changes yet.