CVE-2005-3254

NameCVE-2005-3254
DescriptionThe CGIwrap program before 3.9 on Debian GNU/Linux uses an incorrect minimum value of 100 for a UID to determine whether it can perform a seteuid operation, which could allow attackers to execute code as other system UIDs that are greater than the minimum value, which should be 1000 on Debian systems.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDTSA-6-1
Debian Bugs316881

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
cgiwrapsourceetch3.9-3.0etch1mediumDTSA-6-1
cgiwrapsource(unstable)3.9-3.1low316881

Notes

[sarge] - cgiwrap <no-dsa> (Minor impact)

Search for package or bug name: Reporting problems