CVE-2006-6494Path Traversal in Solaris

4 documents3 sources
Severity
6.6MEDIUMNVD
EPSS
0.0%
top 89.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 13
Latest updateMay 1

Description

Directory traversal vulnerability in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via a .. (dot dot) sequence in the LANG environment variable that points to a locale file containing attacker-controlled format string specifiers.

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 2.7 | Impact: 10.0

Affected Packages2 packages

NVDsun/solaris10.0, 9.0+1
NVDsun/sunos5.8

Patches

🔴Vulnerability Details

3
GHSA
GHSA-7hrq-6276-2m6h: Directory traversal vulnerability in ld2022-05-01
CVEList
CVE-2006-6495: Stack-based buffer overflow in ld2006-12-13
CVEList
CVE-2006-6494: Directory traversal vulnerability in ld2006-12-13
CVE-2006-6494 — Path Traversal in SUN Solaris | cvebase