First published: Fri Oct 27 2006(Updated: )
Buffer overflow in the localtime_r function, and certain other functions, in libc in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long TZ environment variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HPE HP-UX | =11.11 | |
HPE HP-UX | =11.4 | |
HPE HP-UX | =11.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5556 has a high severity rating due to its potential to allow local users to execute arbitrary code.
To fix CVE-2006-5556, ensure your system is updated with the latest patches provided by HPE for HP-UX.
CVE-2006-5556 affects HP-UX versions 11.11, 11.4, and 11.00.
CVE-2006-5556 is a buffer overflow vulnerability that can be exploited through a long TZ environment variable.
CVE-2006-5556 can be exploited by local users with access to the vulnerable system.