CVE-2008-4865

Untrusted search path vulnerability in valgrind before 3.4.0 allows local users to execute arbitrary programs via a Trojan horse .valgrindrc file in the current working directory, as demonstrated using a malicious --db-command options. NOTE: the severity of this issue has been disputed, but CVE is including this issue because execution of a program from an untrusted directory is a common scenario.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:valgrind:valgrind:*:rc1:*:*:*:*:*:*
cpe:2.3:a:valgrind:valgrind:1.9.6:*:*:*:*:*:*:*
cpe:2.3:a:valgrind:valgrind:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:valgrind:valgrind:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:valgrind:valgrind:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:valgrind:valgrind:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:valgrind:valgrind:2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:valgrind:valgrind:2.4.1:*:powerpc:*:*:*:*:*
cpe:2.3:a:valgrind:valgrind:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:valgrind:valgrind:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:valgrind:valgrind:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:valgrind:valgrind:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:valgrind:valgrind:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:valgrind:valgrind:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:valgrind:valgrind:3.2.2:*:*:*:*:*:*:*
cpe:2.3:a:valgrind:valgrind:3.2.3:*:*:*:*:*:*:*
cpe:2.3:a:valgrind:valgrind:3.3.0:*:*:*:*:*:*:*
cpe:2.3:a:valgrind:valgrind:3.3.0:rc1:*:*:*:*:*:*
cpe:2.3:a:valgrind:valgrind:3.3.0:rc2:*:*:*:*:*:*
cpe:2.3:a:valgrind:valgrind:3.3.0:rc3:*:*:*:*:*:*
cpe:2.3:a:valgrind:valgrind:3.3.1:*:*:*:*:*:*:*
cpe:2.3:a:valgrind:valgrind:3.3.1:rc1:*:*:*:*:*:*

History

21 Nov 2024, 00:52

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.html - () http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.html -
References () http://secunia.com/advisories/33568 - Vendor Advisory () http://secunia.com/advisories/33568 - Vendor Advisory
References () http://security.gentoo.org/glsa/glsa-200902-03.xml - () http://security.gentoo.org/glsa/glsa-200902-03.xml -
References () http://sourceforge.net/mailarchive/forum.php?thread_name=200901032045.17604.jseward%40acm.org&forum_name=valgrind-announce - () http://sourceforge.net/mailarchive/forum.php?thread_name=200901032045.17604.jseward%40acm.org&forum_name=valgrind-announce -
References () http://www.openwall.com/lists/oss-security/2008/10/27/4 - () http://www.openwall.com/lists/oss-security/2008/10/27/4 -
References () http://www.openwall.com/lists/oss-security/2008/10/28/5 - () http://www.openwall.com/lists/oss-security/2008/10/28/5 -
References () http://www.openwall.com/lists/oss-security/2008/10/29/5 - () http://www.openwall.com/lists/oss-security/2008/10/29/5 -
References () http://www.openwall.com/lists/oss-security/2008/10/29/9 - () http://www.openwall.com/lists/oss-security/2008/10/29/9 -

Information

Published : 2008-11-01 00:00

Updated : 2024-11-21 00:52


NVD link : CVE-2008-4865

Mitre link : CVE-2008-4865

CVE.ORG link : CVE-2008-4865


JSON object : View

Products Affected

valgrind

  • valgrind