Back

LOW

nspr: setuid root programs linked with NSPR allow elevation of privilege

Published Oct 12, 2006

Description

The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.

Affected products

Remediation

Red Hat statement

This issue also affects other OS that use NSPR. However, Red Hat does not ship any application linked setuid or setgid against NSPR and therefore is not vulnerable to this issue.

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 12, 2006
Updated Aug 7, 2024
Reserved Sep 15, 2006
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Sep 5, 2006