Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-4842

Опубликовано: 12 окт. 2006
Источник: nvd
CVSS2: 3.6
EPSS Средний

Описание

The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:netscape:portable_runtime_api:4.6.1:*:*:*:*:*:*:*
cpe:2.3:a:netscape:portable_runtime_api:4.6.2:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:sun:solaris:10.0:*:sparc:*:*:*:*:*

EPSS

Процентиль: 93%
0.10381
Средний

3.6 Low

CVSS2

Дефекты

CWE-20

Связанные уязвимости

ubuntu
почти 19 лет назад

The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.

redhat
почти 19 лет назад

The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.

debian
почти 19 лет назад

The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in S ...

github
больше 3 лет назад

The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.

EPSS

Процентиль: 93%
0.10381
Средний

3.6 Low

CVSS2

Дефекты

CWE-20