PT-2006-1702 · Suse · Suse Linux+1

Published

2006-02-11

·

Updated

2008-09-05

·

CVE-2006-0646

CVSS v2.0

4.4

Medium

VectorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SUSE Linux versions 9.1 through 10.0 SLES version 9
Description The issue allows local attackers to execute arbitrary code as other users by running an ld-linked application from the current directory, which could contain an attacker-controlled library file, due to ld leaving an empty RPATH or RUNPATH in certain circumstances when linking binaries.
Recommendations For SUSE Linux versions 9.1 through 10.0, consider restricting access to the ld linker to minimize the risk of exploitation. For SLES version 9, avoid running ld-linked applications from untrusted directories until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0646

Affected Products

Sles
Suse Linux