artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges.
References
Link Resource
http://dot.kde.org/1150310128/ Not Applicable
http://mail.gnome.org/archives/beast/2006-December/msg00025.html Mailing List
http://secunia.com/advisories/20677 Broken Link Vendor Advisory
http://secunia.com/advisories/20786 Broken Link Vendor Advisory
http://secunia.com/advisories/20827 Broken Link Vendor Advisory
http://secunia.com/advisories/20868 Broken Link Vendor Advisory
http://secunia.com/advisories/20899 Broken Link Vendor Advisory
http://secunia.com/advisories/25032 Broken Link
http://secunia.com/advisories/25059 Broken Link
http://security.gentoo.org/glsa/glsa-200704-22.xml Third Party Advisory
http://securitytracker.com/id?1016298 Broken Link Third Party Advisory VDB Entry
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.468256 Mailing List Third Party Advisory
http://www.gentoo.org/security/en/glsa/glsa-200606-22.xml Third Party Advisory
http://www.kde.org/info/security/advisory-20060614-2.txt Patch Vendor Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2006:107 Third Party Advisory
http://www.novell.com/linux/security/advisories/2006_38_security.html Broken Link
http://www.osvdb.org/26506 Broken Link
http://www.securityfocus.com/archive/1/437362/100/0/threaded Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/18429 Broken Link Patch Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/23697 Broken Link Third Party Advisory VDB Entry
http://www.vupen.com/english/advisories/2006/2357 Broken Link
http://www.vupen.com/english/advisories/2007/0409 Broken Link
https://exchange.xforce.ibmcloud.com/vulnerabilities/27221 Third Party Advisory VDB Entry
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2006-06-15T10:00:00

Updated: 2018-10-18T14:57:01

Reserved: 2006-06-08T00:00:00


Link: CVE-2006-2916

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2006-06-15T10:02:00.000

Modified: 2024-01-21T01:42:33.730


Link: CVE-2006-2916

JSON object: View

cve-icon Redhat Information

No data.

CWE