CVE-2005-4790
Multiple untrusted search path vulnerabilities in SUSE Linux 9.3 and 10.0, and possibly other distributions, cause the working directory to be added to LD_LIBRARY_PATH, which might allow local users to execute arbitrary code via (1) beagle, (2) tomboy,…
Does this matter?
Lower severity and a low EPSS score (0.48%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple untrusted search path vulnerabilities in SUSE Linux 9.3 and 10.0, and possibly other distributions, cause the working directory to be added to LD_LIBRARY_PATH, which might allow local users to execute arbitrary code via (1) beagle, (2) tomboy, or (3) blam. NOTE: in August 2007, the tomboy vector was reported for other distributions.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.48% probability · 40th percentile
- CISA KEV
- Not listed
- Affected
- novell/suse linux · suse/suse linux
- Source
- cve@mitre.org
References
- http://bugs.gentoo.org/show_bug.cgi?id=188806
- http://bugs.gentoo.org/show_bug.cgi?id=189249
- http://bugs.gentoo.org/show_bug.cgi?id=199841
- http://osvdb.org/39577
- http://osvdb.org/39578
- http://secunia.com/advisories/26480Vendor Advisory
- http://secunia.com/advisories/27608Vendor Advisory
- http://secunia.com/advisories/27621Vendor Advisory
- http://secunia.com/advisories/27799Vendor Advisory
- http://secunia.com/advisories/28339Vendor Advisory
- http://secunia.com/advisories/28672Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200711-12.xml
- http://security.gentoo.org/glsa/glsa-200801-14.xml
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:064
- http://www.novell.com/linux/security/advisories/2005_22_sr.htmlVendor Advisory
- http://www.securityfocus.com/bid/25341
- https://bugzilla.gnome.org/show_bug.cgi?id=485224
- https://bugzilla.redhat.com/show_bug.cgi?id=362941
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36054
- https://usn.ubuntu.com/560-1/
- https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00206.html
- https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00913.html
- http://bugs.gentoo.org/show_bug.cgi?id=188806
- http://bugs.gentoo.org/show_bug.cgi?id=189249
- http://bugs.gentoo.org/show_bug.cgi?id=199841
- http://osvdb.org/39577
- http://osvdb.org/39578
- http://secunia.com/advisories/26480Vendor Advisory
- http://secunia.com/advisories/27608Vendor Advisory
- http://secunia.com/advisories/27621Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.