PT-2006-5598 · Netscape · Netscape Portable Runtime (Nspr) Api
Published
2006-10-12
·
Updated
2018-10-17
·
CVE-2006-4842
CVSS v2.0
3.6
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Netscape Portable Runtime (NSPR) API versions 4.6.1 through 4.6.2
Description
The issue allows local users to create or overwrite arbitrary files because it trusts user-specified environment variables for specifying log files, even when running from setuid programs.
Recommendations
For Netscape Portable Runtime (NSPR) API versions 4.6.1 and 4.6.2, consider restricting the ability of setuid programs to use user-specified environment variables for log file specification until a patch is available.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netscape Portable Runtime (Nspr) Api