6.9
CVSSv2

CVE-2010-4005

Published: 06/11/2010 Updated: 01/03/2011
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1.5.2 and previous versions place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: vector 1 exists because of an incorrect fix for CVE-2005-4790.2.

Vulnerable Product Search on Vulmon Subscribe to Product

gnome tomboy 1.5.1

gnome tomboy 1.4.2

gnome tomboy 1.2.2

gnome tomboy 1.0.1

gnome tomboy

Vendor Advisories

Debian Bug report logs - #605096 CVE-2010-4005 Package: tomboy; Maintainer for tomboy is Debian CLI Applications Team <pkg-cli-apps-team@listsaliothdebianorg>; Source for tomboy is src:tomboy (PTS, buildd, popcon) Affects: tomboy Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sat, 27 Nov 2010 12:15:04 UTC ...