CVE-2005-4790
published 2005-12-31CVE-2005-4790: Multiple untrusted search path vulnerabilities in SUSE Linux 9.3 and 10.0, and possibly other distributions, cause the working directory to be added to…
PriorityP419medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.48%
38.3th percentile
Multiple untrusted search path vulnerabilities in SUSE Linux 9.3 and 10.0, and possibly other distributions, cause the working directory to be added to LD_LIBRARY_PATH, which might allow local users to execute arbitrary code via (1) beagle, (2) tomboy, or (3) blam. NOTE: in August 2007, the tomboy vector was reported for other distributions.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnome | tomboy | <= 1.5.2 | — |
| gnome | tomboy | — | — |
| gnome | tomboy | — | — |
| gnome | tomboy | — | — |
| gnome | tomboy | — | — |
| gnome | tomboy | >= 0 < 1.15.4-0ubuntu1 | 1.15.4-0ubuntu1 |
| novell | suse_linux | — | — |
| suse | suse_linux | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wqwx-hhf2-x4q9: The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1
ghsa_unreviewed·2022-05-17·CVSS 6.9
CVE-2010-4005 [MEDIUM] CWE-94 GHSA-wqwx-hhf2-x4q9: The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1
The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1.5.2 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: vector 1 exists because of an incorrect fix for CVE-2005-4790.2.
GHSA
GHSA-xg82-h5j4-q6gx: Multiple untrusted search path vulnerabilities in SUSE Linux 9
ghsa_unreviewed·2022-05-01
CVE-2005-4790 [MEDIUM] GHSA-xg82-h5j4-q6gx: Multiple untrusted search path vulnerabilities in SUSE Linux 9
Multiple untrusted search path vulnerabilities in SUSE Linux 9.3 and 10.0, and possibly other distributions, cause the working directory to be added to LD_LIBRARY_PATH, which might allow local users to execute arbitrary code via (1) beagle, (2) tomboy, or (3) blam. NOTE: in August 2007, the tomboy vector was reported for other distributions.
OSV
CVE-2010-4005: The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1
osv·2010-11-06·CVSS 6.9
CVE-2010-4005 [MEDIUM] CVE-2010-4005: The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1
The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1.5.2 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: vector 1 exists because of an incorrect fix for CVE-2005-4790.2.
Ubuntu
Tomboy vulnerability
vendor_ubuntu·2008-01-07
CVE-2005-4790 Tomboy vulnerability
Title: Tomboy vulnerability
Summary: Tomboy vulnerability
Jan Oravec discovered that Tomboy did not properly setup the
LD_LIBRARY_PATH environment variable. A local attacker could
exploit this to execute arbitrary code as the user invoking
the program.
Instructions: After a standard system upgrade you need to restart Tomboy to effect
the necessary changes.
Red Hat
tomboy and blam uses insecure LD_LIBRARY_PATH
vendor_redhat·CVSS 6.9
CVE-2005-4790 [MEDIUM] tomboy and blam uses insecure LD_LIBRARY_PATH
tomboy and blam uses insecure LD_LIBRARY_PATH
Multiple untrusted search path vulnerabilities in SUSE Linux 9.3 and 10.0, and possibly other distributions, cause the working directory to be added to LD_LIBRARY_PATH, which might allow local users to execute arbitrary code via (1) beagle, (2) tomboy, or (3) blam. NOTE: in August 2007, the tomboy vector was reported for other distributions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-4790 tomboy includes CWD in LD_LIBRARY_PATH [F8]
bugzilla·2007-11-01·CVSS 6.9
CVE-2005-4790 [MEDIUM] CVE-2005-4790 tomboy includes CWD in LD_LIBRARY_PATH [F8]
CVE-2005-4790 tomboy includes CWD in LD_LIBRARY_PATH [F8]
F8 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
should be fixed in tomboy-0.8.1-2.fc8
---
Could you please make an update?
---
tomboy-0.8.1-3.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2005-4790 tomboy includes CWD in LD_LIBRARY_PATH [F7]
bugzilla·2007-11-01·CVSS 6.9
CVE-2005-4790 [MEDIUM] CVE-2005-4790 tomboy includes CWD in LD_LIBRARY_PATH [F7]
CVE-2005-4790 tomboy includes CWD in LD_LIBRARY_PATH [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
should be fixed in tomboy-0.6.1-2.fc7
---
Could you please make an update?
---
So the build actually failed because of bug 371781. When tomboy-0.6.1-2.fc7 is
built I'll push an update.
---
tomboy-0.6.1-2.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2005-4790 tomboy includes CWD in LD_LIBRARY_PATH [Fdevel]
bugzilla·2007-11-01·CVSS 6.9
CVE-2005-4790 [MEDIUM] CVE-2005-4790 tomboy includes CWD in LD_LIBRARY_PATH [Fdevel]
CVE-2005-4790 tomboy includes CWD in LD_LIBRARY_PATH [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
should be fixed in tomboy-0.8.1-2.fc9
---
or not, the build failed with some odd mono message.
http://koji.fedoraproject.org/koji/getfile?taskID=228366&name=build.log
Bugzilla
CVE-2005-4790 tomboy and blam uses insecure LD_LIBRARY_PATH
bugzilla·2007-08-15·CVSS 6.9
CVE-2005-4790 [MEDIUM] CVE-2005-4790 tomboy and blam uses insecure LD_LIBRARY_PATH
CVE-2005-4790 tomboy and blam uses insecure LD_LIBRARY_PATH
From Gentoo bugzilla:
/usr/bin/tomboy from app-misc/tomboy contains line:
export LD_LIBRARY_PATH="/usr/lib64/tomboy:$LD_LIBRARY_PATH"
which yields to LD_LIBRARY_PATH="/usr/lib64/tomboy:", what means that required
libraries are also looked up in current directory. In the case of tomboy, it is
usually user's home directory, but user may run application from directories
like /tmp as well. If someone is able to copy bogus system libraries to this
directory, user could potentially run enemy code.
Discussion:
A CVE name for the issue has been requested.
---
This is covered by CVE-2005-4790, though it will most likely will get another
CVE name (as CVE-2005-4790 describes more unrelated issues and just for SuSE).
---
Please use
http://bugs.gentoo.org/show_bug.cgi?id=188806http://bugs.gentoo.org/show_bug.cgi?id=189249http://bugs.gentoo.org/show_bug.cgi?id=199841http://osvdb.org/39577http://osvdb.org/39578http://secunia.com/advisories/26480http://secunia.com/advisories/27608http://secunia.com/advisories/27621http://secunia.com/advisories/27799http://secunia.com/advisories/28339http://secunia.com/advisories/28672http://security.gentoo.org/glsa/glsa-200711-12.xmlhttp://security.gentoo.org/glsa/glsa-200801-14.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:064http://www.novell.com/linux/security/advisories/2005_22_sr.htmlhttp://www.securityfocus.com/bid/25341https://bugzilla.gnome.org/show_bug.cgi?id=485224https://bugzilla.redhat.com/show_bug.cgi?id=362941https://exchange.xforce.ibmcloud.com/vulnerabilities/36054https://usn.ubuntu.com/560-1/https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00206.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-November/msg00913.htmlhttp://bugs.gentoo.org/show_bug.cgi?id=188806http://bugs.gentoo.org/show_bug.cgi?id=189249http://bugs.gentoo.org/show_bug.cgi?id=199841http://osvdb.org/39577http://osvdb.org/39578http://secunia.com/advisories/26480http://secunia.com/advisories/27608http://secunia.com/advisories/27621http://secunia.com/advisories/27799http://secunia.com/advisories/28339http://secunia.com/advisories/28672http://security.gentoo.org/glsa/glsa-200711-12.xmlhttp://security.gentoo.org/glsa/glsa-200801-14.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:064http://www.novell.com/linux/security/advisories/2005_22_sr.htmlhttp://www.securityfocus.com/bid/25341https://bugzilla.gnome.org/show_bug.cgi?id=485224https://bugzilla.redhat.com/show_bug.cgi?id=362941https://exchange.xforce.ibmcloud.com/vulnerabilities/36054https://usn.ubuntu.com/560-1/https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00206.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-November/msg00913.html
2005-12-31
Published