← Back

CVE-2006-6494

nvd nist
Published: Dec 13, 2006Modified: Apr 23, 2026

JSON object

Loading...
6.6
Vector
AV:L/AC:M/Au:S/C:C/I:C/A:C
Exploitability: 2.7 / Impact: 10.0
Source: NVD

Description

Directory traversal vulnerability in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via a .. (dot dot) sequence in the LANG environment variable that points to a locale file containing attacker-controlled format string specifiers.

Affected (3)

Products: Sun: Solaris, Sunos
2 products
Solaris
Sunos
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Sun
Version 10.0
Version 9.0
Version 5.8

Timeline

No history available yet.