Privilege Escalation Vulnerability in pppd's Winbind Plugin by Open System Vendors
CVE-2006-2194
Currently unrated
Key Information:
- Status
- Vendor
- CVE Published:
- 5 July 2006
What is CVE-2006-2194?
The winbind plugin in pppd prior to version 2.4.4 lacks proper validation of the setuid function's return code. This flaw allows local users to potentially exploit PAM limits for user processes, preventing the NTLM authentication helper from effectively dropping privileges. This could result in unauthorized access elevation.
