CVE Vulnerabilities

CVE-2006-6494

Published: Dec 13, 2006 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.6 MEDIUM
AV:L/AC:M/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Directory traversal vulnerability in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via a .. (dot dot) sequence in the LANG environment variable that points to a locale file containing attacker-controlled format string specifiers.

Affected Software

Name Vendor Start Version End Version
Solaris Sun 9.0 (including) 9.0 (including)
Solaris Sun 10.0 (including) 10.0 (including)
Sunos Sun 5.8 (including) 5.8 (including)

References