PT-2006-7099 · Sun · Sun Solaris
Published
2006-12-13
·
Updated
2018-10-30
·
CVE-2006-6495
CVSS v2.0
6.6
Medium
| Vector | AV:L/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Sun Solaris versions 8 through 10
Description
The issue is a stack-based buffer overflow in ld.so.1, allowing local users to execute arbitrary code via large precision padding values in a format string specifier in the
format parameter of the doprf function. This issue does not normally cross privilege boundaries, except in cases where malicious message files are introduced externally or if it is leveraged with other vulnerabilities.Recommendations
For Sun Solaris versions 8 through 10, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sun Solaris