---
title: "CVE-2006-4447\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2006-4447?format=md
keywords: index, follow
---

# CVE-2006-4447

Publication date 30 August 2006

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans,
and xterm, does not check the return values for setuid and seteuid calls
when attempting to drop privileges, which might allow local users to gain
privileges by causing those calls to fail, such as by exceeding a ulimit.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| beast | 9.10 karmic | Fixed 0.6.6-8 |
| 9.04 jaunty | Fixed 0.6.6-8 |
| 8.10 intrepid | Fixed 0.6.6-8 |
| 8.04 LTS hardy | Fixed 0.6.6-8 |
| 7.10 gutsy | Fixed 0.6.6-8 |
| 7.04 feisty | Fixed 0.6.6-8 |
| 6.10 edgy | Ignored end of life, was needed |
| 6.06 LTS dapper | Ignored end of life |
| xorg-server | 9.10 karmic | Not affected |
| 9.04 jaunty | Not affected |
| 8.10 intrepid | Not affected |
| 8.04 LTS hardy | Not affected |
| 7.10 gutsy | Not affected |
| 7.04 feisty | Fixed 1.2.0-3ubuntu8 |
| 6.10 edgy | Fixed 1.1.1-0ubuntu12.2 |
| 6.06 LTS dapper | Fixed 1.0.2-0ubuntu10.7 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4447)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2006-4447)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2006-4447)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2006-4447)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2006-4447>
