LWN.net Logo

xnview: privilege escalation

Package(s):xnview CVE #(s):
Created:December 30, 2005 Updated:January 4, 2006
Description: Krzysiek Pawlik of Gentoo Linux discovered that the XnView package for IA32 used the DT_RPATH field insecurely, causing the dynamic loader to search for shared libraries in potentially untrusted directories.
Alerts:
Gentoo 200512-18 2005-12-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds