Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-2110

Overview

Vulnerability Score 2.1 2.1
CVE Id CVE-2006-2110
Last Modified 07 Mar 2011 09:35:16
Published 01 May 2006 03:06:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2006-2110

Summary

Virtual Private Server (Vserver) 2.0.x before 2.0.2-rc18 and 2.1.x before 2.1.1-rc18 provides certain context capabilities (ccaps) that allow local guest users to perform operations that were only intended to be allowed by the guest-root.

Vulnerable Systems

Application

  • Virtual Private Server Vserver 2.0.2

  • Virtual Private Server Vserver 2.1.1


References

MLIST - [Vserver] 20060428 [SECURITY] ccaps not limited to root inside a guest

CONFIRM - http://dev.croup.de/proj/gentoo-vps/browser/vserver-sources/2.0.1-r4/4915_vs2.0.1-vxcapable-fix.patch

VUPEN - ADV-2006-1661

XF - linux-vserver-ccaps-privilege-escalation(26285)

BID - 17842

DEBIAN - DSA-1060

SECUNIA - 20206

SECUNIA - 19961


Last Updated: 27 May 2016 10:42:20