Total vulnerabilities in the database
The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.
Software | From | Fixed in |
---|---|---|
netscape / portable_runtime_api | 4.6.2 | 4.6.2.x |
netscape / portable_runtime_api | 4.6.1 | 4.6.1.x |
sun / solaris | 10.0 | 10.0.x |