6.9
CVSSv2

CVE-2010-4000

Published: 06/11/2010 Updated: 08/11/2010
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

gnome-shell in GNOME Shell 2.31.5 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

Vulnerable Product Search on Vulmon Subscribe to Product

gnome gnome-shell 2.31.5

Vendor Advisories

Debian Bug report logs - #605098 CVE-2010-4000 Package: gnome-shell; Maintainer for gnome-shell is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Source for gnome-shell is src:gnome-shell (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sat, 27 Nov 2010 12:15:11 ...