CVE-2006-4842
Summary
| CVE | CVE-2006-4842 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-10-12 00:07:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:N/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Netscape | Portable Runtime Api | 4.6.1 | All | All | All |
| Application | Netscape | Portable Runtime Api | 4.6.2 | All | All | All |
| Operating System | Sun | Solaris | 10.0 | All | sparc | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| #102658: Security Vulnerability in the Netscape Portable Runtime (NSPR) API Affects Solaris | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| Sun Solaris Netscape Portable Runtime API Local Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Public Advisory: 10.11.06 // iDefense Labs | af854a3a-2127-422b-91ae-364da2661108 | labs.idefense.com | Vendor Advisory |
| Solaris - libnspr NSPR_LOG_FILE Privilege Escalation (Metasploit) - Solaris local Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Solaris Netscape Portable Runtime Privilege Escalation - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Netscape Portable Runtime API Environment Variable Lets Local Users Create Arbitrary Files - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2007-01-11 | Mark J Cox | This issue also affects other OS that use NSPR. However, Red Hat does not ship any application linked setuid or setgid against NSPR and therefore is not vulnerable to this issue. |
There are currently no legacy QID mappings associated with this CVE.