Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-3389

Опубликовано: 30 сент. 2010
Источник: redhat
CVSS2: 3.7

Описание

The (1) SAPDatabase and (2) SAPInstance scripts in OCF Resource Agents (aka resource-agents or cluster-agents) 1.0.3 in Linux-HA place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5rgmanagerAffected
CLuster Suite for RHEL 4rgmanagerFixedRHSA-2011:026416.02.2011
Red Hat Enterprise Linux 5rgmanagerFixedRHSA-2011:100021.07.2011
Red Hat Enterprise Linux 6resource-agentsFixedRHSA-2011:158005.12.2011

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=639044rgmanager: insecure library loading vulnerability

3.7 Low

CVSS2

Связанные уязвимости

ubuntu
больше 14 лет назад

The (1) SAPDatabase and (2) SAPInstance scripts in OCF Resource Agents (aka resource-agents or cluster-agents) 1.0.3 in Linux-HA place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

nvd
больше 14 лет назад

The (1) SAPDatabase and (2) SAPInstance scripts in OCF Resource Agents (aka resource-agents or cluster-agents) 1.0.3 in Linux-HA place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

debian
больше 14 лет назад

The (1) SAPDatabase and (2) SAPInstance scripts in OCF Resource Agents ...

github
около 3 лет назад

The (1) SAPDatabase and (2) SAPInstance scripts in OCF Resource Agents (aka resource-agents or cluster-agents) 1.0.3 in Linux-HA place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

oracle-oval
почти 14 лет назад

ELSA-2011-1000: rgmanager security, bug fix, and enhancement update (LOW)

3.7 Low

CVSS2