6.9
CVSSv2

CVE-2005-4790

Published: 31/12/2005 Updated: 30/10/2018
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple untrusted search path vulnerabilities in SUSE Linux 9.3 and 10.0, and possibly other distributions, cause the working directory to be added to LD_LIBRARY_PATH, which might allow local users to execute arbitrary code via (1) beagle, (2) tomboy, or (3) blam. NOTE: in August 2007, the tomboy vector was reported for other distributions.

Vulnerable Product Search on Vulmon Subscribe to Product

novell suse linux 10.0

suse suse linux 9.3

Vendor Advisories

Jan Oravec discovered that Tomboy did not properly setup the LD_LIBRARY_PATH environment variable A local attacker could exploit this to execute arbitrary code as the user invoking the program ...