|
|
| |
|
| |
couchdb: arbitrary code execution
| Package(s): | couchdb |
CVE #(s): | CVE-2010-2953
|
| Created: | September 9, 2010 |
Updated: | September 21, 2010 |
| Description: |
From the Debian advisory:
Dan Rosenberg discovered that in couchdb, a distributed,
fault-tolerant and schema-free document-oriented database, an insecure
library search path is used; a local attacker could execute arbitrary
code by first dumping a maliciously crafted shared library in some
directory, and then having an administrator run couchdb from this same
directory.
|
| Alerts: |
|
( Log in to post comments)
|
|
|