|
|
| |
|
| |
rgmanager: privilege escalation
| Package(s): | rgmanager |
CVE #(s): | CVE-2010-3389
|
| Created: | July 21, 2011 |
Updated: | December 9, 2011 |
| Description: |
From the Red Hat advisory:
The rgmanager package contains the Red Hat Resource Group Manager, which
provides the ability to create and manage high-availability server
applications in the event of system downtime.
It was discovered that certain resource agent scripts set the
LD_LIBRARY_PATH environment variable to an insecure value containing empty
path elements. A local user able to trick a user running those scripts to
run them while working from an attacker-writable directory could use this
flaw to escalate their privileges via a specially-crafted dynamic library.
|
| Alerts: |
|
( Log in to post comments)
|
|
|