CVE-2006-4842

The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:netscape:portable_runtime_api:4.6.2:*:*:*:*:*:*:*
cpe:2.3:a:netscape:portable_runtime_api:4.6.1:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:sun:solaris:10.0:*:sparc:*:*:*:*:*

Information

Published : 2006-10-11 17:07

Updated : 2018-10-17 14:39


NVD link : CVE-2006-4842

Mitre link : CVE-2006-4842


JSON object : View

CWE
CWE-20

Improper Input Validation

Advertisement

dedicated server usa

Products Affected

netscape

  • portable_runtime_api

sun

  • solaris