CVE-2009-0415: Low severity Monkey Trickle vulnerability
Untrusted search path vulnerability in trickle 1.07 allows local users to execute arbitrary code via a Trojan horse trickle-overload.so in the current working directory, which is referenced in the LDPRELOAD path.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0415?
CVE-2009-0415 is classified as a moderate severity vulnerability due to its potential to allow local users to execute arbitrary code.
How do I fix CVE-2009-0415?
To mitigate CVE-2009-0415, ensure that the trickle software is updated to a version newer than 1.07 or remove the vulnerable version from your system.
Who is affected by CVE-2009-0415?
CVE-2009-0415 affects local users of trickle version 1.07 who can manipulate the current working directory.
What type of vulnerability is CVE-2009-0415?
CVE-2009-0415 is an untrusted search path vulnerability allowing execution of arbitrary code via malicious libraries.
How can I prevent exploitation of CVE-2009-0415?
Prevent exploitation of CVE-2009-0415 by ensuring that LD_PRELOAD is not pointing to directories writable by untrusted users.