CVE-2006-4246
Publication date 19 September 2006
Last updated 17 July 2025
Ubuntu priority
Description
Usermin before 1.220 (20060629) allows remote attackers to read arbitrary files, possibly related to chfn/save.cgi not properly handling an empty shell parameter, which results in changing root’s shell instead of the shell of a specified user.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| usermin | 7.04 feisty | Not in release |
| 6.10 edgy | Not in release | |
| 6.06 LTS dapper | Not in release |