CVE-2010-3389

The (1) SAPDatabase and (2) SAPInstance scripts in OCF Resource Agents (aka resource-agents or cluster-agents) 1.0.3 in Linux-HA place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Configurations

Configuration 1 (hide)

cpe:2.3:a:linux-ha:ocf_resource_agents:1.0.3:*:*:*:*:*:*:*

History

No history.

Information

Published : 2010-10-20 18:00

Updated : 2024-02-04 17:54


NVD link : CVE-2010-3389

Mitre link : CVE-2010-3389

CVE.ORG link : CVE-2010-3389


JSON object : View

Products Affected

linux-ha

  • ocf_resource_agents