CVE-2010-4005
published 2010-11-06CVE-2010-4005: The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1.5.2 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows local…
PriorityP419medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.41%
33.6th percentile
The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1.5.2 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: vector 1 exists because of an incorrect fix for CVE-2005-4790.2.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnome | tomboy | <= 1.5.2 | — |
| gnome | tomboy | — | — |
| gnome | tomboy | — | — |
| gnome | tomboy | — | — |
| gnome | tomboy | — | — |
| gnome | tomboy | >= 0 < 1.15.4-0ubuntu1 | 1.15.4-0ubuntu1 |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wqwx-hhf2-x4q9: The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1
ghsa_unreviewed·2022-05-17·CVSS 6.9
CVE-2010-4005 [MEDIUM] CWE-94 GHSA-wqwx-hhf2-x4q9: The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1
The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1.5.2 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: vector 1 exists because of an incorrect fix for CVE-2005-4790.2.
OSV
CVE-2010-4005: The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1
osv·2010-11-06·CVSS 6.9
CVE-2010-4005 [MEDIUM] CVE-2010-4005: The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1
The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1.5.2 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: vector 1 exists because of an incorrect fix for CVE-2005-4790.2.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4005 tomboy: insecure library loading vulnerability [fedora-all]
bugzilla·2010-10-20·CVSS 6.9
CVE-2010-4005 [MEDIUM] CVE-2010-4005 tomboy: insecure library loading vulnerability [fedora-all]
CVE-2010-4005 tomboy: insecure library loading vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=644606
Please note: this issue affects multiple
Bugzilla
CVE-2010-4005 tomboy: insecure library loading vulnerability
bugzilla·2010-10-19·CVSS 6.9
CVE-2010-4005 [MEDIUM] CVE-2010-4005 tomboy: insecure library loading vulnerability
CVE-2010-4005 tomboy: insecure library loading vulnerability
Ludwig Nussel discovered that tomboy contained a script that could be abused by an attacker to execute arbitrary code.
The vulnerability is due to an insecure change to LD_LIBRARY_PATH, and environment variable used by ld.so(8) to look for libraries in directories other than the standard paths. When there is an empty item in the colon-separated list of directories in LD_LIBRARY_PATH, ld.so(8) treats it as a '.' (current working directory). If the given script is executed from a directory where a local attacker could write files, there is a chance for exploitation.
In Fedora, both /usr/bin/tomboy and /usr/bin/tomboy-panel re-set LD_LIBRARY_PATH insecurely:
export LD_LIBRARY_PATH="/usr/lib/tomboy${LD_LIBRARY_PATH+:$LD_LIBRARY_P
http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:035http://www.vupen.com/english/advisories/2011/0457https://bugzilla.redhat.com/show_bug.cgi?id=644606http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:035http://www.vupen.com/english/advisories/2011/0457https://bugzilla.redhat.com/show_bug.cgi?id=644606
2010-11-06
Published