CVE-2005-4790: Medium severity SUSE SuSE Linux vulnerability
Multiple untrusted search path vulnerabilities in SUSE Linux 9.3 and 10.0, and possibly other distributions, cause the working directory to be added to LDLIBRARYPATH, which might allow local users to execute arbitrary code via (1) beagle, (2) tomboy, or (3) blam. NOTE: in August 2007, the tomboy vector was reported for other distributions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4790?
CVE-2005-4790 is classified as a medium severity vulnerability due to the potential for local users to execute arbitrary code.
How do I fix CVE-2005-4790?
To fix CVE-2005-4790, ensure that the LD_LIBRARY_PATH does not include the current working directory or apply security updates for affected SUSE Linux versions.
Which versions of SUSE Linux are affected by CVE-2005-4790?
CVE-2005-4790 affects SUSE Linux versions 9.3 and 10.0.
What applications are associated with CVE-2005-4790 vulnerabilities?
CVE-2005-4790 vulnerabilities are associated with the applications beagle, tomboy, and blam.
Is CVE-2005-4790 exploitable remotely?
CVE-2005-4790 is not remotely exploitable; it requires local user access to exploit the vulnerability.