Privilege Escalation Vulnerability in pppd's Winbind Plugin by Open System Vendors
CVE-2006-2194

Currently unrated

What is CVE-2006-2194?

The winbind plugin in pppd prior to version 2.4.4 lacks proper validation of the setuid function's return code. This flaw allows local users to potentially exploit PAM limits for user processes, preventing the NTLM authentication helper from effectively dropping privileges. This could result in unauthorized access elevation.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.