CVE-2006-4246

Publication date 19 September 2006

Last updated 17 July 2025


Ubuntu priority

Description

Usermin before 1.220 (20060629) allows remote attackers to read arbitrary files, possibly related to chfn/save.cgi not properly handling an empty shell parameter, which results in changing root’s shell instead of the shell of a specified user.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
usermin 7.04 feisty Not in release
6.10 edgy Not in release
6.06 LTS dapper Not in release