CVE-2005-4791: Low severity Novell SUSE Linux vulnerability
Published Dec 31, 2005
·Updated
Multiple untrusted search path vulnerabilities in SUSE Linux 10.0 cause the working directory to be added to LDLIBRARYPATH, which might allow local users to execute arbitrary code via (1) liferea or (2) banshee.
Affected Software
1 affected component
Novell SUSE Linux=10.0
Remediation
Event History
Dec 31, 2005
CVE Published
05:00 AM
Apr 27, 2006
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-4791?
CVE-2005-4791 has a medium severity rating due to the potential for local code execution.
2
How do I fix CVE-2005-4791?
To fix CVE-2005-4791, remove the working directory from the LD_LIBRARY_PATH environment variable.
3
Which applications are affected by CVE-2005-4791?
CVE-2005-4791 specifically affects the Liferea and Banshee applications on SUSE Linux 10.0.
4
Who is impacted by CVE-2005-4791?
Local users of SUSE Linux 10.0 are impacted by CVE-2005-4791 due to the vulnerabilities in application configurations.
5
Is CVE-2005-4791 specific to a certain version of SUSE Linux?
Yes, CVE-2005-4791 is specific to SUSE Linux version 10.0.