PT-2006-5598 · Netscape · Netscape Portable Runtime (Nspr) Api

Publicado

2006-10-12

·

Atualizado

2018-10-17

·

CVE-2006-4842

CVSS v2.0

3.6

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Netscape Portable Runtime (NSPR) API versions 4.6.1 through 4.6.2
Description The issue allows local users to create or overwrite arbitrary files because it trusts user-specified environment variables for specifying log files, even when running from setuid programs.
Recommendations For Netscape Portable Runtime (NSPR) API versions 4.6.1 and 4.6.2, consider restricting the ability of setuid programs to use user-specified environment variables for log file specification until a patch is available.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-4842

Produtos afetados

Netscape Portable Runtime (Nspr) Api