First published: Tue Oct 19 2010(Updated: )
gnome-shell in GNOME Shell 2.31.5 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu Yaru Theme for GNOME Shell | =2.31.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4000 has a medium severity, allowing local users to potentially gain elevated privileges.
To fix CVE-2010-4000, upgrade to a version of GNOME Shell that does not include this vulnerability.
The issue in CVE-2010-4000 was discovered by Ludwig Nussel.
CVE-2010-4000 specifically affects GNOME Shell version 2.31.5.
CVE-2010-4000 enables local users to execute a Trojan horse shared library in the current working directory.