PT-2006-5598 · Netscape · Netscape Portable Runtime (Nspr) Api
Publicado
2006-10-12
·
Atualizado
2018-10-17
·
CVE-2006-4842
CVSS v2.0
3.6
Baixa
| Vetor | AV:L/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Netscape Portable Runtime (NSPR) API versions 4.6.1 through 4.6.2
Description
The issue allows local users to create or overwrite arbitrary files because it trusts user-specified environment variables for specifying log files, even when running from setuid programs.
Recommendations
For Netscape Portable Runtime (NSPR) API versions 4.6.1 and 4.6.2, consider restricting the ability of setuid programs to use user-specified environment variables for log file specification until a patch is available.
Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Netscape Portable Runtime (Nspr) Api