6.9
CVSSv2

CVE-2010-3374

Published: 04/10/2010 Updated: 05/10/2010
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Qt Creator prior to 2.0.1 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

Vulnerable Product Search on Vulmon Subscribe to Product

nokia qt creator 2.0.0

nokia qt creator 1.3.1

nokia qt creator 1.1.0

nokia qt creator 0.9.2

nokia qt creator 1.3.0

nokia qt creator 1.2.90

nokia qt creator 1.2.0

nokia qt creator

nokia qt creator 1.0.0

nokia qt creator 0.9.1

Vendor Advisories

Debian Bug report logs - #598300 qtcreator: CVE-2010-3374: insecure library loading Package: qtcreator; Maintainer for qtcreator is Debian Qt/KDE Maintainers <debian-qt-kde@listsdebianorg>; Source for qtcreator is src:qtcreator (PTS, buildd, popcon) Reported by: Raphael Geissert <geissert@debianorg> Date: Tue, 28 ...