Executive Summary

Informations
Name CVE-2006-6494 First vendor Publication 2006-12-12
Vendor Cve Last vendor Modification 2018-10-30

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:M/Au:S/C:C/I:C/A:C)
Cvss Base Score 6.6 Attack Range Local
Cvss Impact Score 10 Attack Complexity Medium
Cvss Expoit Score 2.7 Authentication Requires single instance
Calculate full CVSS 2.0 Vectors scores

Detail

Directory traversal vulnerability in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via a .. (dot dot) sequence in the LANG environment variable that points to a locale file containing attacker-controlled format string specifiers.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6494

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:2121
 
Oval ID: oval:org.mitre.oval:def:2121
Title: Security Vulnerabilities in Solaris ld.so.1(1) may Lead to Execution of Arbitrary Code with Elevated Privileges
Description: Directory traversal vulnerability in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via a .. (dot dot) sequence in the LANG environment variable that points to a locale file containing attacker-controlled format string specifiers.
Family: unix Class: vulnerability
Reference(s): CVE-2006-6494
Version: 1
Platform(s): Sun Solaris 8
Sun Solaris 9
Sun Solaris 10
Product(s):
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 2
Os 1

Open Source Vulnerability Database (OSVDB)

Id Description
30843 Solaris ld.so LANG Variable Traversal Local Privilege Escalation

Sources (Detail)

Source Url
BID http://www.securityfocus.com/bid/21564
IDEFENSE http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=449
OVAL https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
SECTRACK http://securitytracker.com/id?1017376
SECUNIA http://secunia.com/advisories/23317
SUNALERT http://sunsolve.sun.com/search/document.do?assetkey=1-26-102724-1
VUPEN http://www.vupen.com/english/advisories/2006/4979
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/30849

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
Date Informations
2021-05-04 12:04:59
  • Multiple Updates
2021-04-22 01:05:35
  • Multiple Updates
2020-05-23 00:18:50
  • Multiple Updates
2018-10-31 00:19:47
  • Multiple Updates
2017-10-11 09:23:47
  • Multiple Updates
2017-07-29 12:01:49
  • Multiple Updates
2016-06-28 16:01:23
  • Multiple Updates
2016-04-26 15:25:20
  • Multiple Updates
2013-05-11 11:16:49
  • Multiple Updates