First published: Sun Dec 10 2006(Updated: )
Buffer overflow in the POSIX Threads library (libpthread) on HP Tru64 UNIX 4.0F PK8, 4.0G PK4, and 5.1A PK6 allows local users to gain root privileges via a long PTHREAD_CONFIG environment variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP Tru64 UNIX | =4.0f-pk8 | |
HP Tru64 UNIX | =5.1a-pk6 | |
HP Tru64 UNIX | =4.0g-pk4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6418 has a high severity level due to its potential for local users to gain root privileges.
CVE-2006-6418 exploits a buffer overflow in the POSIX Threads library by manipulating a long PTHREAD_CONFIG environment variable.
CVE-2006-6418 affects HP Tru64 UNIX versions 4.0F PK8, 4.0G PK4, and 5.1A PK6.
To fix CVE-2006-6418, apply the latest security patches provided by HP for the affected Tru64 UNIX versions.
A possible workaround for CVE-2006-6418 is to limit the use of the PTHREAD_CONFIG environment variable or restrict local user access.