LWN.net Logo

couchdb: arbitrary code execution

Package(s):couchdb CVE #(s):CVE-2010-2953
Created:September 9, 2010 Updated:September 21, 2010
Description:

From the Debian advisory:

Dan Rosenberg discovered that in couchdb, a distributed, fault-tolerant and schema-free document-oriented database, an insecure library search path is used; a local attacker could execute arbitrary code by first dumping a maliciously crafted shared library in some directory, and then having an administrator run couchdb from this same directory.

Alerts:
Fedora FEDORA-2010-13665 2010-08-27
Fedora FEDORA-2010-13640 2010-08-27
Debian DSA-2107-1 2010-09-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds