← Back

CVE-2006-0646

nvd nist
Published: Feb 11, 2006Modified: Apr 16, 2026

JSON object

Loading...
4.4
Vector
AV:L/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 3.4 / Impact: 6.4
Source: NVD

Description

ld in SUSE Linux 9.1 through 10.0, and SLES 9, in certain circumstances when linking binaries, can leave an empty RPATH or RUNPATH, which allows local attackers to execute arbitrary code as other users via by running an ld-linked application from the current directory, which could contain an attacker-controlled library file.

Affected (11)

Products: Suse: Suse Linux
1 product
Suse Linux
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Suse
Version 10.0
Version 9.0
Version 9.1
Version 9.1
Version 9.1
Version 9.2
Version 9.2
Version 9.2
Version 9.3
Version 9.3
Version 9.3

References (6)

Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.