CVE Database
/

CVE-2010-3998

Back to search

CVE-2010-3998

Published: Nov 5, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

The (1) banshee-1 and (2) muinshee scripts in Banshee 1.8.0 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: Banshee might also be affected using GST_PLUGIN_PATH.

VendorProductVersions

n/a

n/a

affected
n/a

References

FEDORA-2010-16907
vendor-advisory
x_refsource_FEDORA
FEDORA-2010-17021
vendor-advisory
x_refsource_FEDORA
44752
vdb-entry
x_refsource_BID
42237
third-party-advisory
x_refsource_SECUNIA
42234
third-party-advisory
x_refsource_SECUNIA
ADV-2010-2964
vdb-entry
x_refsource_VUPEN
MDVSA-2011:034
vendor-advisory
x_refsource_MANDRIVA
FEDORA-2010-16916
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now