CVE Vulnerabilities

CVE-2006-6165

Published: Nov 29, 2006 | Modified: May 17, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

ld.so in FreeBSD, NetBSD, and possibly other BSD distributions does not remove certain harmful environment variables, which allows local users to gain privileges by passing certain environment variables to loading processes. NOTE: this issue has been disputed by a third party, stating that it is the responsibility of the application to properly sanitize the environment

Affected Software

Name Vendor Start Version End Version
Freebsd Freebsd 6.2-stable (including) 6.2-stable (including)
Netbsd Netbsd 2.0.4 (including) 2.0.4 (including)

References