CVE-2006-0646
Last modified
CVE-2006-0646 is a vulnerability of currently unknown severity. ld in SUSE Linux 9.1 through 10.0, and SLES 9, in certain circumstances when linking binaries, can leave an empty RPATH or RUNPATH, which allows local attackers to execute arbitrary code as other users via by running an ld-linked application from the current directory, which could contain an attacker-controlled library file.. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
ld in SUSE Linux 9.1 through 10.0, and SLES 9, in certain circumstances when linking binaries, can leave an empty RPATH or RUNPATH, which allows local attackers to execute arbitrary code as other users via by running an ld-linked application from the current directory, which could contain an attacker-controlled library file.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Suse | Suse Linux | 9.0 |
| Suse | Suse Linux | 9.1 |
| Suse | Suse Linux | 9.2 |
| Suse | Suse Linux | 9.3 |
| Suse | Suse Linux | 10.0 |
References
- http://lists.suse.com/archive/suse-security-announce/2006-Feb/0003.htmlPatch, Vendor Advisory
- http://lists.suse.com/archive/suse-security-announce/2006-Feb/0003.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-0646?
How severe is CVE-2006-0646?
How do I fix CVE-2006-0646?
Are you affected by CVE-2006-0646?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
