CVE-2006-4842
Solaris 10 libnspr - 'Constructor' Arbitrary File Creation Privilege Escalation
Severity Score
3.6
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
6
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.
Las API 4.6.1 y 4.6.2 de Netscape Portable Runtime (NSPR), usadas en Sun Solaris 10, permiten variables de entorno definidas por el usuario para especificar ficheros de traza incluso cuando se ejecutan desde programas Setuid, que permiten a los usuarios locales crear o sobre-escribir ficheros de su elección.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2006-09-15 CVE Reserved
- 2006-10-12 CVE Published
- 2006-10-13 First Exploit
- 2024-08-07 CVE Updated
- 2024-09-01 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (20)
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/2641 | 2006-10-24 | |
https://www.exploit-db.com/exploits/2543 | 2006-10-13 | |
https://www.exploit-db.com/exploits/2569 | 2006-10-16 | |
https://www.exploit-db.com/exploits/45433 | 2024-08-07 | |
https://www.exploit-db.com/exploits/28789 | 2006-10-24 | |
https://www.exploit-db.com/exploits/28788 | 2006-10-13 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=418 | 2018-10-17 | |
http://secunia.com/advisories/22348 | 2018-10-17 | |
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102658-1 | 2018-10-17 | |
http://www.vupen.com/english/advisories/2006/4016 | 2018-10-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Netscape Search vendor "Netscape" | Portable Runtime Api Search vendor "Netscape" for product "Portable Runtime Api" | 4.6.1 Search vendor "Netscape" for product "Portable Runtime Api" and version "4.6.1" | - |
Affected
| ||||||
Netscape Search vendor "Netscape" | Portable Runtime Api Search vendor "Netscape" for product "Portable Runtime Api" | 4.6.2 Search vendor "Netscape" for product "Portable Runtime Api" and version "4.6.2" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Solaris Search vendor "Sun" for product "Solaris" | 10.0 Search vendor "Sun" for product "Solaris" and version "10.0" | sparc |
Affected
|