vendor:
Solaris 10
by:
Marco Ivaldi
7,2
CVSS
HIGH
Design Error Vulnerability
20
CWE
Product Name: Solaris 10
Affected Version From: Solaris 10
Affected Version To: Solaris 10
Patch Exists: YES
Related CWE: CVE-2006-4842
CPE: o:sun:sunos:10
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: SPARC, x86
2006
raptor_libnspr3 – Solaris 10 libnspr constructor exploit
Local exploitation of a design error vulnerability in version 4.6.1 of NSPR, as included with Sun Microsystems Solaris 10, allows attackers to create or overwrite arbitrary files on the system. The problem exists because environment variables are used to create log files. Even when the program is setuid, users can specify a log file that will be created with elevated privileges (CVE-2006-4842).
Mitigation:
Apply the patch 119213-10 for SPARC and 119214-10 for x86.