PT-2006-1702 · Suse · Suse Linux+1
Published
2006-02-11
·
Updated
2008-09-05
·
CVE-2006-0646
CVSS v2.0
4.4
Medium
| Vector | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SUSE Linux versions 9.1 through 10.0
SLES version 9
Description
The issue allows local attackers to execute arbitrary code as other users by running an ld-linked application from the current directory, which could contain an attacker-controlled library file, due to ld leaving an empty RPATH or RUNPATH in certain circumstances when linking binaries.
Recommendations
For SUSE Linux versions 9.1 through 10.0, consider restricting access to the ld linker to minimize the risk of exploitation.
For SLES version 9, avoid running ld-linked applications from untrusted directories until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sles
Suse Linux