CVE-2010-3357

gnome-subtitles 1.0 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pedro_castro:gnome-subtitles:1.0:*:*:*:*:*:*:*

History

21 Nov 2024, 01:18

Type Values Removed Values Added
References () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=598289 - Exploit, Patch () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=598289 - Exploit, Patch
References () http://git.gnome.org/browse/gnome-subtitles/commit/?id=44370dc2a87f7fa0d6c9730979514bd407a37c65 - Patch () http://git.gnome.org/browse/gnome-subtitles/commit/?id=44370dc2a87f7fa0d6c9730979514bd407a37c65 - Patch
References () http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049184.html - () http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049184.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049275.html - () http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049275.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049288.html - () http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049288.html -
References () http://secunia.com/advisories/41807 - () http://secunia.com/advisories/41807 -

Information

Published : 2010-10-20 18:00

Updated : 2025-04-11 00:51


NVD link : CVE-2010-3357

Mitre link : CVE-2010-3357

CVE.ORG link : CVE-2010-3357


JSON object : View

Products Affected

pedro_castro

  • gnome-subtitles