VYPR
High severity7.8NVD Advisory· Published Jun 15, 2006· Updated Apr 16, 2026

CVE-2006-2916

CVE-2006-2916

Description

artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges.

Affected products

2
  • KDE/Arts2 versions
    cpe:2.3:a:kde:arts:1.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:kde:arts:1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:kde:arts:1.2:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

23

News mentions

0

No linked articles in our index yet.