CVE-2006-4803: Code Injection
Published Sep 14, 2006
·Updated
The Fan-Out Linux and UNIX receiver scripts in Novell Identity Manager (IDM) 3.0.1 allows local users to execute arbitrary commands via unspecified vectors involving certain environment variables and "code injection."
Affected Software
1 affected component
NetIQ Identity Manager=3.0.1
Remediation
Patch Available
Event History
Sep 14, 2006
CVE Published
10:07 PM
Sep 15, 2006
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4803?
CVE-2006-4803 has a moderate severity rating due to its potential for local users to execute arbitrary commands.
2
How do I fix CVE-2006-4803?
To fix CVE-2006-4803, update to a later version of Novell Identity Manager that addresses this vulnerability.
3
Who is affected by CVE-2006-4803?
Local users on systems running Novell Identity Manager 3.0.1 are affected by CVE-2006-4803.
4
What kind of attacks does CVE-2006-4803 allow?
CVE-2006-4803 allows local users to perform code injection attacks through certain environment variables.
5
Is CVE-2006-4803 a remote attack vulnerability?
No, CVE-2006-4803 is not a remote attack vulnerability; it requires local user access.