CVE-2006-4307
published 2006-08-23CVE-2006-4307: Unspecified vulnerability in the format command in Sun Solaris 8 and 9 before 20060821 allows local users to modify arbitrary files via unspecified vectors…
PriorityP422high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.35%
26.7th percentile
Unspecified vulnerability in the format command in Sun Solaris 8 and 9 before 20060821 allows local users to modify arbitrary files via unspecified vectors involving profiles that permit running format with elevated privileges, a different issue than CVE-2006-4306 and CVE-2006-4319.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | solaris | — | — |
| sun | solaris | — | — |
| sun | solaris | — | — |
| sun | sunos | — | — |
| sun | sunos | — | — |
| sun | sunos | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c8hg-m2xp-c7q4: Unspecified vulnerability in the format command in Sun Solaris 8 and 9 before 20060821 allows local users to modify arbitrary files via unspecified ve
ghsa_unreviewed·2022-05-01·CVSS 7.2
CVE-2006-4307 [HIGH] GHSA-c8hg-m2xp-c7q4: Unspecified vulnerability in the format command in Sun Solaris 8 and 9 before 20060821 allows local users to modify arbitrary files via unspecified ve
Unspecified vulnerability in the format command in Sun Solaris 8 and 9 before 20060821 allows local users to modify arbitrary files via unspecified vectors involving profiles that permit running format with elevated privileges, a different issue than CVE-2006-4306 and CVE-2006-4319.
GHSA
GHSA-m89g-rg2j-xwwq: Buffer overflow in the format command in Solaris 8, 9, and 10 allows local users with access to format (such as the "File System Management" RBAC prof
ghsa_unreviewed·2022-05-01·CVSS 7.2
CVE-2006-4319 [HIGH] GHSA-m89g-rg2j-xwwq: Buffer overflow in the format command in Solaris 8, 9, and 10 allows local users with access to format (such as the "File System Management" RBAC prof
Buffer overflow in the format command in Solaris 8, 9, and 10 allows local users with access to format (such as the "File System Management" RBAC profile) to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2006-4307.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/21581http://secunia.com/advisories/22295http://securitytracker.com/id?1016726http://sunsolve.sun.com/search/document.do?assetkey=1-26-102514-1http://support.avaya.com/elmodocs2/security/ASA-2006-205.htmhttp://www.securityfocus.com/bid/19647http://www.vupen.com/english/advisories/2006/3355https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1573http://secunia.com/advisories/21581http://secunia.com/advisories/22295http://securitytracker.com/id?1016726http://sunsolve.sun.com/search/document.do?assetkey=1-26-102514-1http://support.avaya.com/elmodocs2/security/ASA-2006-205.htmhttp://www.securityfocus.com/bid/19647http://www.vupen.com/english/advisories/2006/3355https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1573
2006-08-23
Published