CVE-2006-6165: High severity FreeBSD FreeBSD vulnerability
DISPUTED ld.so in FreeBSD, NetBSD, and possibly other BSD distributions does not remove certain harmful environment variables, which allows local users to gain privileges by passing certain environment variables to loading processes. NOTE: this issue has been disputed by a third party, stating that it is the responsibility of the application to properly sanitize the environment.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6165?
The severity of CVE-2006-6165 is considered moderate due to potential local privilege escalation.
How do I fix CVE-2006-6165?
To fix CVE-2006-6165, ensure that your operating system is updated to a patched version that mitigates the handling of harmful environment variables.
Which systems are affected by CVE-2006-6165?
CVE-2006-6165 affects FreeBSD and NetBSD systems, specifically version 2.0.4 of NetBSD and 6.2-stable of FreeBSD.
Can CVE-2006-6165 be exploited remotely?
No, CVE-2006-6165 can only be exploited locally by logged-in users with the ability to modify environment variables.
Is CVE-2006-6165 still a relevant vulnerability?
While CVE-2006-6165 is an older vulnerability, its relevance depends on the use of the affected BSD systems and their current security posture.