|
|
| |
|
| |
banshee: privilege escalation
| Package(s): | banshee |
CVE #(s): | CVE-2010-3998
|
| Created: | November 12, 2010 |
Updated: | February 22, 2011 |
| Description: |
From the CVE entry:
The (1) banshee-1 and (2) muinshee scripts in Banshee 1.8.0 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. |
| Alerts: |
|
( Log in to post comments)
|
|
|