CVE-2010-4337
published 2011-01-14CVE-2010-4337: The configure script in gnash 0.8.8 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/gnash-configure-errors.$$, (2)…
PriorityP48low3.3CVSS 2.0
AVLACMAuNCNIPAP
EPSS
0.34%
26.1th percentile
The configure script in gnash 0.8.8 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/gnash-configure-errors.$$, (2) /tmp/gnash-configure-warnings.$$, or (3) /tmp/gnash-configure-recommended.$$ files.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | gnash | — | — |
| gnu | gnash | >= 0 < 0.8.11~git20130903-3ubuntu1 | 0.8.11~git20130903-3ubuntu1 |
| gnu | gnash | >= 0 < 0.8.11~git20160109-1build1 | 0.8.11~git20160109-1build1 |
CVSS provenance
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
osv3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fh37-hpvh-9h6c: The configure script in gnash 0
ghsa_unreviewed·2022-05-17
CVE-2010-4337 [LOW] CWE-59 GHSA-fh37-hpvh-9h6c: The configure script in gnash 0
The configure script in gnash 0.8.8 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/gnash-configure-errors.$$, (2) /tmp/gnash-configure-warnings.$$, or (3) /tmp/gnash-configure-recommended.$$ files.
OSV
CVE-2010-4337: The configure script in gnash 0
osv·2011-01-14·CVSS 3.3
CVE-2010-4337 [LOW] CVE-2010-4337: The configure script in gnash 0
The configure script in gnash 0.8.8 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/gnash-configure-errors.$$, (2) /tmp/gnash-configure-warnings.$$, or (3) /tmp/gnash-configure-recommended.$$ files.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4337 gnash: symlink attack via configure script [fedora-all]
bugzilla·2011-01-15·CVSS 3.3
CVE-2010-4337 [LOW] CVE-2010-4337 gnash: symlink attack via configure script [fedora-all]
CVE-2010-4337 gnash: symlink attack via configure script [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=669851
Please note: this issue affects multiple supp
Bugzilla
CVE-2010-4337 gnash: symlink attack via configure script
bugzilla·2011-01-15·CVSS 3.3
CVE-2010-4337 [LOW] CVE-2010-4337 gnash: symlink attack via configure script
CVE-2010-4337 gnash: symlink attack via configure script
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-4337 to
the following vulnerability:
Name: CVE-2010-4337
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4337
Assigned: 20101130
Reference: MISC: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=605419
Reference: BID:45102
Reference: URL: http://www.securityfocus.com/bid/45102
Reference: OSVDB:69533
Reference: URL: http://www.osvdb.org/69533
Reference: SECUNIA:42416
Reference: URL: http://secunia.com/advisories/42416
The configure script in gnash 0.8.8 allows local users to overwrite
arbitrary files via a symlink attack on the (1)
/tmp/gnash-configure-errors.$$, (2) /tmp/gnash-configure-warnings.$$,
or (3) /tmp/gnash-configure-recommended.$$ files.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=605419http://secunia.com/advisories/42416http://secunia.com/advisories/48466http://www.debian.org/security/2012/dsa-2435http://www.osvdb.org/69533http://www.securityfocus.com/bid/45102http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=605419http://secunia.com/advisories/42416http://secunia.com/advisories/48466http://www.debian.org/security/2012/dsa-2435http://www.osvdb.org/69533http://www.securityfocus.com/bid/45102
2011-01-14
Published