CVE-2006-4842

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
12/10/2006
Last modified:
17/10/2018

Description

The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netscape:portable_runtime_api:4.6.1:*:*:*:*:*:*:*
cpe:2.3:a:netscape:portable_runtime_api:4.6.2:*:*:*:*:*:*:*
cpe:2.3:o:sun:solaris:10.0:*:sparc:*:*:*:*:*