The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/20471 | vdb entry |
http://www.vupen.com/english/advisories/2006/4016 | vdb entry vendor advisory |
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=418 | third party advisory vendor advisory |
http://www.securityfocus.com/archive/1/448691/100/0/threaded | mailing list |
https://www.exploit-db.com/exploits/45433/ | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/29489 | vdb entry |
http://secunia.com/advisories/22348 | third party advisory vendor advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1819 | signature vdb entry |
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102658-1 | vendor advisory |
http://securitytracker.com/id?1017050 | vdb entry |