Description
Multiple untrusted search path vulnerabilities in SUSE Linux 10.0 cause the working directory to be added to LD_LIBRARY_PATH, which might allow local users to execute arbitrary code via (1) liferea or (2) banshee.
CVSS vector
AV:L/AC:L/C:N/I:P/A:NExploitability: 3.9 | Impact: 2.9Complexity: Low
Confidentiality: None
Availability: None
Affected Packages3 packages
🔴Vulnerability Details
3GHSAGHSA-53f4-27hf-367h: Multiple untrusted search path vulnerabilities in SUSE Linux 10↗2022-05-01 ▶ CVEListCVE-2005-4791: Multiple untrusted search path vulnerabilities in SUSE Linux 10↗2006-04-26 ▶ OSVCVE-2005-4791: Multiple untrusted search path vulnerabilities in SUSE Linux 10↗2005-12-31 ▶ 📋Vendor Advisories
2DebianCVE-2005-4791: beagle - Multiple untrusted search path vulnerabilities in SUSE Linux 10.0 cause the work...↗2005 ▶ Red Hatliferea uses insecure LD_LIBRARY_PATH↗ ▶ 💬Community
1BugzillaCVE-2005-4791 liferea uses insecure LD_LIBRARY_PATH↗2007-11-20 ▶