Ardour 'LD_LIBRARY_PATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
BID:44106
Info
Ardour 'LD_LIBRARY_PATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 44106 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-3349 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 28 2010 12:00AM |
| Updated: | Apr 13 2015 10:17PM |
| Credit: | Rapheal Geissert |
| Vulnerable: |
Ardour Ardour 2.8.11 |
| Not Vulnerable: | |
Discussion
Ardour 'LD_LIBRARY_PATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
Ardour is prone to a vulnerability that lets attackers execute arbitrary code.
A successful exploit can allow the attacker to execute arbitrary code in the context of the user running the affected application.
Ardour 2.8.11 is vulnerable; other versions may also be affected.
Ardour is prone to a vulnerability that lets attackers execute arbitrary code.
A successful exploit can allow the attacker to execute arbitrary code in the context of the user running the affected application.
Ardour 2.8.11 is vulnerable; other versions may also be affected.
Exploit / POC
Ardour 'LD_LIBRARY_PATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
Attackers can exploit the issue using standard commands.
Attackers can exploit the issue using standard commands.
Solution / Fix
Ardour 'LD_LIBRARY_PATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Ardour 'LD_LIBRARY_PATH' Insecure Library Loading Arbitrary Code Execution Vulnerability
References:
References:
- ardour: CVE-2010-3349: insecure library loading (Debian Bug report logs - #598283)
- ardour: insecure library loading vulnerability (Red HAt Bugzilla- Bug 638365)
- Product Page (Ardour)