Tomboy LD_LIBRARY_PATH Environment Variable Local Privilege Escalation Vulnerability
BID:25341
Info
Tomboy LD_LIBRARY_PATH Environment Variable Local Privilege Escalation Vulnerability
| Bugtraq ID: | 25341 |
| Class: | Design Error |
| CVE: |
CVE-2005-4790 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 16 2007 12:00AM |
| Updated: | Mar 07 2008 10:01PM |
| Credit: | Jan Oravec is credited with discovering this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Redhat Fedora 7 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Gentoo Linux Blam Blam 1.8.3 Alex Graveley Tomboy 0.8.1 Alex Graveley Tomboy 0.7.4 |
| Not Vulnerable: | |
Discussion
Tomboy LD_LIBRARY_PATH Environment Variable Local Privilege Escalation Vulnerability
Tomboy is prone to a local privilege-escalation vulnerability.
Exploiting this issue allows local attackers to execute arbitrary code with the privileges of the user running the affected application.
Tomboy is prone to a local privilege-escalation vulnerability.
Exploiting this issue allows local attackers to execute arbitrary code with the privileges of the user running the affected application.
Exploit / POC
Tomboy LD_LIBRARY_PATH Environment Variable Local Privilege Escalation Vulnerability
An attacker can exploit this issue by gaining local interactive access to the affected computer.
An attacker can exploit this issue by gaining local interactive access to the affected computer.
Solution / Fix
Tomboy LD_LIBRARY_PATH Environment Variable Local Privilege Escalation Vulnerability
Solution:
Please see the referenced advisories for information on obtaining and applying the appropriate updates.
Solution:
Please see the referenced advisories for information on obtaining and applying the appropriate updates.
References
Tomboy LD_LIBRARY_PATH Environment Variable Local Privilege Escalation Vulnerability
References:
References:
- Tomboy Home Page (Alex Graveley)
- Gentoo Bugzilla Bug 188806 (Jan Oravec)