---
title: "CVE-2006-3083\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2006-3083?format=md
keywords: index, follow
---

# CVE-2006-3083

Publication date 9 August 2006

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The (1) krshd and (2) v4rcp applications in (a) MIT Kerberos 5 (krb5) up to
1.5, and 1.4.x before 1.4.4, when running on Linux and AIX, and (b) Heimdal
0.7.2 and earlier, do not check return codes for setuid calls, which allows
local users to gain privileges by causing setuid to fail to drop privileges
using attacks such as resource exhaustion.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| krb5 | 7.04 feisty | Fixed 1.4.4-5ubuntu3.3 |
| 6.10 edgy | Fixed 1.4.3-9ubuntu1.5 |
| 6.06 LTS dapper | Fixed 1.4.3-5ubuntu0.6 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3083)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2006-3083)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2006-3083)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2006-3083)

### Related Ubuntu Security Notices (USN)

+ [USN-334-1](https://usn.ubuntu.com/USN-334-1)
+ krb5 vulnerabilities
+ 16 August 2006

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2006-3083>
