CVE-2006-5556
HP-UX B.11.11 - Buffer Overflow via Long TZ Environment Variable
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5556. PoCs published by prdelka.
AI-analyzed exploit summary This exploit targets a stack overflow in HP-UX libc's handling of the TZ environment variable. It uses the 'su' binary to escalate privileges to root by overflowing the buffer with a crafted payload containing shellcode.
Description
Buffer overflow in the localtime_r function, and certain other functions, in libc in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long TZ environment variable.
Exploits (1)
This exploit targets a stack overflow in HP-UX libc's handling of the TZ environment variable. It uses the 'su' binary to escalate privileges to root by overflowing the buffer with a crafted payload containing shellcode.