First published: Mon Aug 20 2007(Updated: )
Untrusted search path vulnerability in the wrapper scripts for the (1) rug, (2) zen-updater, (3) zen-installer, and (4) zen-remover programs on SUSE Linux 10.1 and Enterprise 10 allows local users to gain privileges via modified (a) LD_LIBRARY_PATH and (b) MONO_GAC_PREFIX environment variables.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Linux | =10.1 | |
SUSE Linux | =10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4432 is classified as a high severity vulnerability due to the potential for local privilege escalation.
To mitigate CVE-2007-4432, ensure that environment variables such as LD_LIBRARY_PATH and MONO_GAC_PREFIX are not set to untrusted directories and apply any available patches or updates from SUSE.
CVE-2007-4432 affects users running SUSE Linux 10.1 and SUSE Linux Enterprise 10.
CVE-2007-4432 can be exploited through local attacks where a user can manipulate library paths to execute arbitrary code with elevated privileges.
No, CVE-2007-4432 is not a remote vulnerability; it requires local access to the system to be exploited.