CVE-2010-3354: Medium severity dropbox vulnerability
dropboxd in Dropbox 0.7.110 places a zero-length directory name in the LDLIBRARYPATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3354?
CVE-2010-3354 has been classified as a moderate severity vulnerability due to its potential to allow local privilege escalation.
How do I fix CVE-2010-3354?
To fix CVE-2010-3354, you should update to a version of Dropbox that is not vulnerable to this issue, preferably a version released after 0.7.110.
What are the risks associated with CVE-2010-3354?
The main risk associated with CVE-2010-3354 is that a local user could exploit the vulnerability to execute arbitrary code with elevated privileges.
Who is affected by CVE-2010-3354?
Users of Dropbox version 0.7.110 running on systems where local malicious users have access are affected by CVE-2010-3354.
What is CVE-2010-3354 about?
CVE-2010-3354 is a vulnerability that allows local users to gain privileges via manipulation of the LD_LIBRARY_PATH environment variable in Dropbox.