LWN.net Logo

nip2: privilege escalation

Package(s):nip2 CVE #(s):CVE-2010-3364
Created:August 23, 2011 Updated:August 24, 2011
Description: From the CVE entry:

The vips-7.22 script in VIPS 7.22.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

Alerts:
Fedora FEDORA-2011-10781 2011-08-13
Fedora FEDORA-2011-10808 2011-08-13
Fedora FEDORA-2011-10781 2011-08-13
Fedora FEDORA-2011-10808 2011-08-13

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds