CVE-2006-2194

The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which might allow local users to gain privileges by causing setuid to fail, such as exceeding PAM limits for the maximum number of user processes, which prevents the winbind NTLM authentication helper from dropping privileges.

Published: 2006-07-05 Last update: 2026-04-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2006-2194 is rated Moderate Risk (40.1/100): CVSS High severity, with low exploitation likelihood (EPSS 0.40%). Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2006-2194

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.06% 0.40% +0.34%
2 2025-03-17 0.04% 0.06% +0.01%
3 2024-12-17 0.04%

Full EPSS history (6 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2006-2194

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.2 2.0 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
3.9 10.0 [email protected]

Weakness enumeration for CVE-2006-2194

OS Trackers for CVE-2006-2194

vendor priority summary link
debian medium CVE-2006-2194 medium priority: Debian including 1 source packages (ppp), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2006-2194
redhat https://access.redhat.com/security/cve/CVE-2006-2194
ubuntu medium CVE-2006-2194 medium priority: Ubuntu including 1 source packages (ppp), 4 status rows across 4 suites (dapper, edgy, feisty, upstream): released 3, needs-triage 1. https://ubuntu.com/security/CVE-2006-2194

Vendor comments (NVD) for CVE-2006-2194

  • Red Hat (2006-08-16T00:00:00)

    Not vulnerable. The winbind plugin is not shipped with Red Hat Enterprise Linux 2.1, 3, or 4.

Affected software / configurations for CVE-2006-2194

Vendor Product Version Raw CPE
point-to-point_protocol_project point-to-point_protocol <= 2.4.4 cpe:2.3:a:point-to-point_protocol_project:point-to-point_protocol:*:*:*:*:*:*:*:*

References for CVE-2006-2194

cvelogic Threat Intelligence