CVE-2010-4000Gnome-shell vulnerability

CWE-2649 documents7 sources
Severity
6.9MEDIUMNVD
EPSS
0.0%
top 85.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 6
Latest updateMay 17

Description

gnome-shell in GNOME Shell 2.31.5 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 3.4 | Impact: 10.0

Affected Packages2 packages

Debiangnome/gnome-shell< 2.91.3-1+3
NVDgnome/gnome-shell2.31.5

🔴Vulnerability Details

3
GHSA
GHSA-gm3m-g83g-8676: gnome-shell in GNOME Shell 22022-05-17
OSV
CVE-2010-4000: gnome-shell in GNOME Shell 22010-11-06
CVEList
CVE-2010-4000: gnome-shell in GNOME Shell 22010-11-05

💥Exploits & PoCs

1
Exploit-DB
ecava IntegraXor 3.6.4000.0 - Directory Traversal2010-12-21

📋Vendor Advisories

1
Debian
CVE-2010-4000: gnome-shell - gnome-shell in GNOME Shell 2.31.5 places a zero-length directory name in the LD_...2010

💬Community

3
Bugzilla
OpenJDK Incomplete Fix for CVE-2010-44692011-02-18
Bugzilla
CVE-2010-4000 gnome-shell: insecure library loading vulnerability [fedora-all]2010-10-20
Bugzilla
CVE-2010-4000 gnome-shell: insecure library loading vulnerability2010-10-19
CVE-2010-4000 — Gnome Gnome-shell vulnerability | cvebase