CVE-2006-6164
Estado: ModificadaAlta (7.2)—
The _dl_unsetenv function in loader.c in the ELF ld.so in OpenBSD 3.9 and 4.0 does not properly remove duplicate environment variables, which allows local users to pass dangerous variables such as LD_PRELOAD to loading processes, which might be leveraged to gain privileges.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 7.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.33%
- Percentil entre todas las CVEs puntuadas: 24
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://secunia.com/advisories/22993
- http://securitytracker.com/id?1017253
- http://www.matasano.com/log/592/finger-79tcp-mcdonald-dowd-and-schuh-challenge-part-2/
- http://www.openbsd.org/errata.html#ldso
- http://www.openbsd.org/errata39.html#ldso
- http://www.securityfocus.com/archive/1/452371/100/0/threaded
- http://www.securityfocus.com/archive/1/452428/100/0/threaded
- http://www.securityfocus.com/bid/21188
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30441
- http://secunia.com/advisories/22993
- http://securitytracker.com/id?1017253
- http://www.matasano.com/log/592/finger-79tcp-mcdonald-dowd-and-schuh-challenge-part-2/
- http://www.openbsd.org/errata.html#ldso
- http://www.openbsd.org/errata39.html#ldso
- http://www.securityfocus.com/archive/1/452371/100/0/threaded
- http://www.securityfocus.com/archive/1/452428/100/0/threaded
- http://www.securityfocus.com/bid/21188
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30441
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-6164",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-11-29T01:28:00.000",
"references": [
{
"url": "http://secunia.com/advisories/22993",
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1017253",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.matasano.com/log/592/finger-79tcp-mcdonald-dowd-and-schuh-challenge-part-2/",
"source": "cve@mitre.org"
},
{
"url": "http://www.openbsd.org/errata.html#ldso",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.openbsd.org/errata39.html#ldso",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/452371/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/452428/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/21188",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30441",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/22993",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securitytracker.com/id?1017253",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.matasano.com/log/592/finger-79tcp-mcdonald-dowd-and-schuh-challenge-part-2/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openbsd.org/errata.html#ldso",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openbsd.org/errata39.html#ldso",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/452371/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/452428/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/21188",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30441",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The _dl_unsetenv function in loader.c in the ELF ld.so in OpenBSD 3.9 and 4.0 does not properly remove duplicate environment variables, which allows local users to pass dangerous variables such as LD_PRELOAD to loading processes, which might be leveraged to gain privileges."
},
{
"lang": "es",
"value": "La función _dl_unsetenv en loader.c en el ELF ld.so en OpenBSD 3.9 y 4.0 no borra adecuadamente variables de entorno duplicadas, lo cual permite a usuarios locales pasar variables peligrosas como LD_PRELOAD a procesos de carga, lo cual puede ser utilizado para obtener privilegios."
}
],
"lastModified": "2026-06-16T22:32:35.703",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:openbsd:openbsd:3.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F5BB6C5D-4C43-4BB8-B1CE-A70BBE650CA1"
},
{
"criteria": "cpe:2.3:o:openbsd:openbsd:4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CC77812C-D84E-493E-9D21-1BA6C2129E70"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}