7.2
CVSSv2

CVE-2006-6165

Published: 29/11/2006 Updated: 11/04/2024
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

ld.so in FreeBSD, NetBSD, and possibly other BSD distributions does not remove certain harmful environment variables, which allows local users to gain privileges by passing certain environment variables to loading processes. NOTE: this issue has been disputed by a third party, stating that it is the responsibility of the application to properly sanitize the environment

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

netbsd netbsd 2.0.4

freebsd freebsd 6.2