First published: Mon Oct 04 2010(Updated: )
Qt Creator before 2.0.1 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nokia Qt Creator | =2.0.0-rc1 | |
Nokia Qt Creator | =0.9.2-rc1 | |
Nokia Qt Creator | =1.3.0-rc1 | |
Nokia Qt Creator | =2.0.0-alpha | |
Nokia Qt Creator | =1.3.1 | |
Nokia Qt Creator | =1.2.90 | |
Nokia Qt Creator | =1.1.0-rc1 | |
Nokia Qt Creator | =1.1.0 | |
Nokia Qt Creator | =1.3.0-beta | |
Nokia Qt Creator | =1.3.0 | |
Nokia Qt Creator | <=2.0.0 | |
Nokia Qt Creator | =1.0.0 | |
Nokia Qt Creator | =2.0.0-beta | |
Nokia Qt Creator | =1.2.0 | |
Nokia Qt Creator | =0.9.1-beta |
http://www.qt.gitorious.org/qt-creator/qt-creator/commit/3c00715c8e90c57953ec4a8716110f6954e524e4
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3374 is classified as a high severity vulnerability due to the potential for local privilege escalation.
To fix CVE-2010-3374, update Qt Creator to version 2.0.1 or later.
CVE-2010-3374 affects multiple versions of Nokia Qt Creator prior to 2.0.1.
Exploiting CVE-2010-3374 allows local users to gain elevated privileges through a Trojan horse shared library.
Local users on systems running affected versions of Qt Creator are at risk from CVE-2010-3374.