CVE-2006-6494 — Path Traversal in Solaris
4 documents3 sources
Severity
6.6MEDIUMNVD
EPSS
0.0%
top 89.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 13
Latest updateMay 1
Description
Directory traversal vulnerability in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via a .. (dot dot) sequence in the LANG environment variable that points to a locale file containing attacker-controlled format string specifiers.
CVSS vector
AV:L/AC:M/C:C/I:C/A:CExploitability: 2.7 | Impact: 10.0