Vulnerability Description
chpst in runit 1.3.3-1 for Debian GNU/Linux, when compiled on little endian i386 machines against dietlibc, does not properly handle when multiple groups are specified in the -u option, which causes chpst to assign permissions for the root group due to inconsistent bit sizes for the gid_t type.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Runit | Runit | 1.3.3.1 |
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=356016ExploitPatchVendor Advisory
- http://secunia.com/advisories/19323
- http://www.securityfocus.com/bid/17179
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25419
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=356016ExploitPatchVendor Advisory
- http://secunia.com/advisories/19323
- http://www.securityfocus.com/bid/17179
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25419
FAQ
What is CVE-2006-1319?
CVE-2006-1319 is a vulnerability with a CVSS score of 6.2 (MEDIUM). chpst in runit 1.3.3-1 for Debian GNU/Linux, when compiled on little endian i386 machines against dietlibc, does not properly handle when multiple groups are specified in the -u option, which causes c...
How severe is CVE-2006-1319?
CVE-2006-1319 has been rated MEDIUM with a CVSS base score of 6.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-1319?
Check the references section above for vendor advisories and patch information. Affected products include: Runit Runit.