Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-4001

Опубликовано: 06 нояб. 2010
Источник: nvd
CVSS2: 4.6
EPSS Низкий

Описание

GMXRC.bash in Gromacs 4.5.1 and earlier places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: CVE disputes this issue because the GMXLDLIB value is always added to the beginning of LD_LIBRARY_PATH at a later point in the script

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:gromacs:gromacs:*:*:*:*:*:*:*:*
Версия до 4.5.1 (включая)
cpe:2.3:o:fedoraproject:fedora:*:*:*:*:*:*:*:*

EPSS

Процентиль: 18%
0.00056
Низкий

4.6 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
больше 15 лет назад

GMXRC.bash in Gromacs 4.5.1 and earlier places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: CVE disputes this issue because the GMXLDLIB value is always added to the beginning of LD_LIBRARY_PATH at a later point in the script

debian
больше 15 лет назад

GMXRC.bash in Gromacs 4.5.1 and earlier places a zero-length directory ...

github
больше 3 лет назад

** DISPUTED ** GMXRC.bash in Gromacs 4.5.1 and earlier places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: CVE disputes this issue because the GMXLDLIB value is always added to the beginning of LD_LIBRARY_PATH at a later point in the script.

EPSS

Процентиль: 18%
0.00056
Низкий

4.6 Medium

CVSS2

Дефекты

CWE-264