CVE-2010-3364: Medium severity vtk vulnerability
Published Oct 20, 2010
·Updated
The vips-7.22 script in VIPS 7.22.2 places a zero-length directory name in the LDLIBRARYPATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Affected Software
1 affected component
vips vips=7.22.2
Event History
Oct 20, 2010
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-3364?
CVE-2010-3364 is considered a moderate severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2010-3364?
To fix CVE-2010-3364, upgrade to a patched version of VIPS higher than 7.22.2.
3
Who is affected by CVE-2010-3364?
CVE-2010-3364 affects users of VIPS version 7.22.2, particularly on local systems.
4
What kind of exploit is possible with CVE-2010-3364?
CVE-2010-3364 can be exploited by local users to execute a Trojan horse shared library via manipulation of the LD_LIBRARY_PATH.
5
Is CVE-2010-3364 a remote or local vulnerability?
CVE-2010-3364 is a local vulnerability that requires access to the affected system to exploit.