nspr: setuid root programs linked with NSPR allow elevation of privilege
Published Oct 12, 2006
3.6
LOWCVSS 2.0
EPSS 7.62%
Description
The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.
Affected products
No data.
Configuration 1
- 4.6.1
- 4.6.2
No data.
Red Hat Enterprise Linux 4
nspr
Not affected
Red Hat Enterprise Linux 5
nspr
Not affected
Red Hat Enterprise Linux 6
nspr
Not affected
Red Hat Enterprise Linux 7
nspr
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | nspr | Not affected | n/a |
| Red Hat Enterprise Linux 5 | nspr | Not affected | n/a |
| Red Hat Enterprise Linux 6 | nspr | Not affected | n/a |
| Red Hat Enterprise Linux 7 | nspr | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue also affects other OS that use NSPR. However, Red Hat does not ship any application linked setuid or setgid against NSPR and therefore is not vulnerable to this issue.
References (14)
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=418 third-party-advisoryx_refsource_IDEFENSEVendor Advisory
- http://secunia.com/advisories/22348 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securitytracker.com/id?1017050 vdb-entryx_refsource_SECTRACK
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102658-1 vendor-advisoryx_refsource_SUNALERT
- http://www.securityfocus.com/archive/1/448691/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/20471 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2006/4016 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2006-4842 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1253692 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29489 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2006-4842
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1819 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2006-4842
- https://www.exploit-db.com/exploits/45433/ exploitx_refsource_EXPLOIT-DB
Change history (0)
No recorded changes yet.