CVE-2006-4842

Exp

The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.

Published: 2006-10-12 Last update: 2026-04-23 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2006-4842 is rated High Exploit Risk (61.4/100): CVSS Low severity, with high exploitation likelihood (EPSS 11.38%, 94th percentile). Core evidence: 6 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2006-4842

EDB-ID Source Kind Published Link
45433 exploit_db edb 2018-09-18 Exploit-DB ↗
28789 exploit_db edb 2006-10-24 Exploit-DB ↗
2641 exploit_db edb 2006-10-24 Exploit-DB ↗
2569 exploit_db edb 2006-10-16 Exploit-DB ↗
28788 exploit_db edb 2006-10-13 Exploit-DB ↗
2543 exploit_db edb 2006-10-13 Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2006-4842

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-04 12.20% 11.38% -0.82%
2 2025-12-26 10.70% 12.20% +1.50%
3 2025-09-22 10.70%

Full EPSS history (14 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2006-4842

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
3.6 2.0 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:P Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
3.9 4.9 [email protected]

Weakness enumeration for CVE-2006-4842

OS Trackers for CVE-2006-4842

vendor priority summary link
alpine CVE-2006-4842: no source package rows; 0 state rows across 0 repos (none); fixed 0, open 0. https://security.alpinelinux.org/vuln/CVE-2006-4842
redhat high https://access.redhat.com/security/cve/CVE-2006-4842
ubuntu medium CVE-2006-4842 medium priority: Ubuntu including 1 source packages (firefox), 4 status rows across 4 suites (dapper, edgy, feisty, upstream): not-affected 3, needs-triage 1. https://ubuntu.com/security/CVE-2006-4842

Vendor comments (NVD) for CVE-2006-4842

  • Red Hat (2007-01-11T00:00:00)

    This issue also affects other OS that use NSPR. However, Red Hat does not ship any application linked setuid or setgid against NSPR and therefore is not vulnerable to this issue.

Affected software / configurations for CVE-2006-4842

Vendor Product Version Raw CPE
netscape portable_runtime_api 4.6.1 cpe:2.3:a:netscape:portable_runtime_api:4.6.1:*:*:*:*:*:*:*
netscape portable_runtime_api 4.6.2 cpe:2.3:a:netscape:portable_runtime_api:4.6.2:*:*:*:*:*:*:*
sun solaris 10.0 cpe:2.3:o:sun:solaris:10.0:*:sparc:*:*:*:*:*

References for CVE-2006-4842

cvelogic Threat Intelligence