CVE-2010-2953

5 documents5 sources
Severity
6.9MEDIUM
EPSS
0.1%
top 65.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 14
Latest updateMay 17

Description

Untrusted search path vulnerability in a certain Debian GNU/Linux patch for the couchdb script in CouchDB 0.8.0 allows local users to gain privileges via a crafted shared library in the current working directory.

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 3.4 | Impact: 10.0

Affected Packages1 packages

NVDapache/couchdb0.8.0

🔴Vulnerability Details

2
GHSA
GHSA-3qjx-2c9m-cjpj: Untrusted search path vulnerability in a certain Debian GNU/Linux patch for the couchdb script in CouchDB 02022-05-17
CVEList
CVE-2010-2953: Untrusted search path vulnerability in a certain Debian GNU/Linux patch for the couchdb script in CouchDB 02010-09-14

📋Vendor Advisories

1
Red Hat
couchdb: start-up script sets insecure LD_LIBRARY_PATH

💬Community

1
Bugzilla
CVE-2010-2953 couchdb: start-up script sets insecure LD_LIBRARY_PATH2010-08-26
CVE-2010-2953 (MEDIUM CVSS 6.9) | Untrusted search path vulnerability | cvebase.io