Описание
The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.
The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2006-4842
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29489
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1819
- https://www.exploit-db.com/exploits/45433
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=418
- http://secunia.com/advisories/22348
- http://securitytracker.com/id?1017050
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102658-1
- http://www.securityfocus.com/archive/1/448691/100/0/threaded
- http://www.securityfocus.com/bid/20471
- http://www.vupen.com/english/advisories/2006/4016
Связанные уязвимости
The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.
The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.
The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.
The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in S ...