Lucene search

K
cveMitreCVE-2006-0646
HistoryFeb 11, 2006 - 11:02 a.m.

CVE-2006-0646

2006-02-1111:02:00
mitre
web.nvd.nist.gov
43
cve
2006
0646
vulnerability
suse linux
sles 9
security
local attack
arbitrary code
nvd

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

High

EPSS

0

Percentile

5.1%

ld in SUSE Linux 9.1 through 10.0, and SLES 9, in certain circumstances when linking binaries, can leave an empty RPATH or RUNPATH, which allows local attackers to execute arbitrary code as other users via by running an ld-linked application from the current directory, which could contain an attacker-controlled library file.

Affected configurations

Nvd
Node
susesuse_linuxMatch9.0enterprise_server
OR
susesuse_linuxMatch9.1personal
OR
susesuse_linuxMatch9.1professional
OR
susesuse_linuxMatch9.1x86_64
OR
susesuse_linuxMatch9.2personal
OR
susesuse_linuxMatch9.2professional
OR
susesuse_linuxMatch9.2x86_64
OR
susesuse_linuxMatch9.3personal
OR
susesuse_linuxMatch9.3professional
OR
susesuse_linuxMatch9.3x86_64
OR
susesuse_linuxMatch10.0professional
VendorProductVersionCPE
susesuse_linux9.0cpe:2.3:o:suse:suse_linux:9.0:*:enterprise_server:*:*:*:*:*
susesuse_linux9.1cpe:2.3:o:suse:suse_linux:9.1:*:personal:*:*:*:*:*
susesuse_linux9.1cpe:2.3:o:suse:suse_linux:9.1:*:professional:*:*:*:*:*
susesuse_linux9.1cpe:2.3:o:suse:suse_linux:9.1:*:x86_64:*:*:*:*:*
susesuse_linux9.2cpe:2.3:o:suse:suse_linux:9.2:*:personal:*:*:*:*:*
susesuse_linux9.2cpe:2.3:o:suse:suse_linux:9.2:*:professional:*:*:*:*:*
susesuse_linux9.2cpe:2.3:o:suse:suse_linux:9.2:*:x86_64:*:*:*:*:*
susesuse_linux9.3cpe:2.3:o:suse:suse_linux:9.3:*:personal:*:*:*:*:*
susesuse_linux9.3cpe:2.3:o:suse:suse_linux:9.3:*:professional:*:*:*:*:*
susesuse_linux9.3cpe:2.3:o:suse:suse_linux:9.3:*:x86_64:*:*:*:*:*
Rows per page:
1-10 of 111

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2006-0646