LWN.net Logo

banshee: privilege escalation

Package(s):banshee CVE #(s):CVE-2010-3998
Created:November 12, 2010 Updated:February 22, 2011
Description: From the CVE entry:

The (1) banshee-1 and (2) muinshee scripts in Banshee 1.8.0 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

Alerts:
Mandriva MDVSA-2011:034 2011-02-21
Fedora FEDORA-2010-16907 2010-10-28
Fedora FEDORA-2010-16916 2010-10-28
Fedora FEDORA-2010-17021 2010-10-31

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds