Unrated severityNVD Advisory· Published May 28, 2006· Updated Apr 16, 2026
CVE-2006-1174
CVE-2006-1174
Description
useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly allows attackers to read or modify the mailbox.
Affected products
8cpe:2.3:a:debian:shadow:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:debian:shadow:*:*:*:*:*:*:*:*range: <=4.0.7
- cpe:2.3:a:debian:shadow:4.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:debian:shadow:4.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:debian:shadow:4.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:debian:shadow:4.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:debian:shadow:4.0.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:debian:shadow:4.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:debian:shadow:4.0.6:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
26- secunia.com/advisories/20370nvdPatchVendor Advisory
- www.securityfocus.com/bid/18111nvdPatch
- secunia.com/advisories/20506nvdVendor Advisory
- secunia.com/advisories/25098nvdVendor Advisory
- secunia.com/advisories/25267nvdVendor Advisory
- secunia.com/advisories/25629nvdVendor Advisory
- secunia.com/advisories/25894nvdVendor Advisory
- secunia.com/advisories/25896nvdVendor Advisory
- secunia.com/advisories/26909nvdVendor Advisory
- secunia.com/advisories/27706nvdVendor Advisory
- www.vupen.com/english/advisories/2006/2006nvdVendor Advisory
- www.vupen.com/english/advisories/2007/3229nvdVendor Advisory
- www.kb.cert.org/vuls/id/312692nvdUS Government Resource
- patches.sgi.com/support/free/security/advisories/20070602-01-P.ascnvd
- cvs.pld.org.pl/shadow/NEWSnvd
- lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.htmlnvd
- support.avaya.com/elmodocs2/security/ASA-2007-249.htmnvd
- www.gentoo.org/security/en/glsa/glsa-200606-02.xmlnvd
- www.mandriva.com/security/advisoriesnvd
- www.redhat.com/support/errata/RHSA-2007-0276.htmlnvd
- www.redhat.com/support/errata/RHSA-2007-0431.htmlnvd
- www.securityfocus.com/archive/1/468336/100/0/threadednvd
- www.securitytracker.com/idnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/26958nvd
- issues.rpath.com/browse/RPL-1357nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10807nvd
News mentions
0No linked articles in our index yet.