CVE-2006-4842

The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:netscape:portable_runtime_api:4.6.1:*:*:*:*:*:*:*
cpe:2.3:a:netscape:portable_runtime_api:4.6.2:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:sun:solaris:10.0:*:sparc:*:*:*:*:*

History

No history.

Information

Published : 2006-10-12 00:07

Updated : 2023-12-10 10:40


NVD link : CVE-2006-4842

Mitre link : CVE-2006-4842

CVE.ORG link : CVE-2006-4842


JSON object : View

Products Affected

sun

  • solaris

netscape

  • portable_runtime_api
CWE
CWE-20

Improper Input Validation