banshee: privilege escalation
| Package(s): | banshee | CVE #(s): | CVE-2010-3998 | ||||||||||||||||||||
| Created: | November 12, 2010 | Updated: | February 5, 2014 | ||||||||||||||||||||
| Description: | From the CVE entry:
The (1) banshee-1 and (2) muinshee scripts in Banshee 1.8.0 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. | ||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||
