Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-3374

Опубликовано: 04 окт. 2010
Источник: nvd
CVSS2: 6.9
EPSS Низкий

Описание

Qt Creator before 2.0.1 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

Комментарий

Per: http://qt.nokia.com/about/news/security-announcement-qt-creator-2.0.0-for-desktop-platforms

'The issue does not affect Windows or Mac OS X.'

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:nokia:qt_creator:*:*:*:*:*:*:*:*
Версия до 2.0.0 (включая)
cpe:2.3:a:nokia:qt_creator:0.9.1:beta:*:*:*:*:*:*
cpe:2.3:a:nokia:qt_creator:0.9.2:rc1:*:*:*:*:*:*
cpe:2.3:a:nokia:qt_creator:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:nokia:qt_creator:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:nokia:qt_creator:1.1.0:rc1:*:*:*:*:*:*
cpe:2.3:a:nokia:qt_creator:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:nokia:qt_creator:1.2.90:*:*:*:*:*:*:*
cpe:2.3:a:nokia:qt_creator:1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:nokia:qt_creator:1.3.0:beta:*:*:*:*:*:*
cpe:2.3:a:nokia:qt_creator:1.3.0:rc1:*:*:*:*:*:*
cpe:2.3:a:nokia:qt_creator:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:nokia:qt_creator:2.0.0:alpha:*:*:*:*:*:*
cpe:2.3:a:nokia:qt_creator:2.0.0:beta:*:*:*:*:*:*
cpe:2.3:a:nokia:qt_creator:2.0.0:rc1:*:*:*:*:*:*

EPSS

Процентиль: 14%
0.00047
Низкий

6.9 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
около 15 лет назад

Qt Creator before 2.0.1 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

debian
около 15 лет назад

Qt Creator before 2.0.1 places a zero-length directory name in the LD_ ...

github
больше 3 лет назад

Qt Creator before 2.0.1 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

EPSS

Процентиль: 14%
0.00047
Низкий

6.9 Medium

CVSS2

Дефекты

NVD-CWE-Other