Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2006-4842

Опубликовано: 12 окт. 2006
Источник: debian
EPSS Средний

Описание

The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xulrunnerfixed1.8.0.9-1package
mozillano-dsasargepackage

Примечания

  • could not find setuid binary in sid, but evolution-data-server has a setgid mail binary

  • see https://bugzilla.mozilla.org/show_bug.cgi?id=351470

EPSS

Процентиль: 93%
0.10381
Средний

Связанные уязвимости

ubuntu
почти 19 лет назад

The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.

redhat
почти 19 лет назад

The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.

nvd
почти 19 лет назад

The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.

github
больше 3 лет назад

The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.

EPSS

Процентиль: 93%
0.10381
Средний