CVE-2006-6494: Medium severity Sun SunOS vulnerability
Directory traversal vulnerability in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via a .. (dot dot) sequence in the LANG environment variable that points to a locale file containing attacker-controlled format string specifiers.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6494?
CVE-2006-6494 is considered a critical vulnerability due to the potential for local users to execute arbitrary code.
How do I fix CVE-2006-6494?
To mitigate CVE-2006-6494, users should update their Solaris systems to the latest patches provided by Oracle.
Who is affected by CVE-2006-6494?
CVE-2006-6494 affects local users of Sun Solaris 8, 9, and 10 on SPARC architecture.
What type of attack does CVE-2006-6494 enable?
CVE-2006-6494 enables local users to perform directory traversal attacks leading to arbitrary code execution.
Is CVE-2006-6494 a remote or local vulnerability?
CVE-2006-6494 is a local vulnerability, requiring access to the affected system to exploit.