Lucene search

K
cveMitreCVE-2010-4005
HistoryNov 06, 2010 - 12:00 a.m.

CVE-2010-4005

2010-11-0600:00:02
CWE-94
mitre
web.nvd.nist.gov
22
cve-2010-4005
nvd
tomboy
gnome
information security
privilege escalation
vulnerability

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.1

Confidence

Low

EPSS

0.001

Percentile

27.8%

The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1.5.2 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: vector 1 exists because of an incorrect fix for CVE-2005-4790.2.

Affected configurations

Nvd
Node
gnometomboyRange1.5.2
OR
gnometomboyMatch1.0.1
OR
gnometomboyMatch1.2.2
OR
gnometomboyMatch1.4.2
OR
gnometomboyMatch1.5.1
VendorProductVersionCPE
gnometomboy*cpe:2.3:a:gnome:tomboy:*:*:*:*:*:*:*:*
gnometomboy1.0.1cpe:2.3:a:gnome:tomboy:1.0.1:*:*:*:*:*:*:*
gnometomboy1.2.2cpe:2.3:a:gnome:tomboy:1.2.2:*:*:*:*:*:*:*
gnometomboy1.4.2cpe:2.3:a:gnome:tomboy:1.4.2:*:*:*:*:*:*:*
gnometomboy1.5.1cpe:2.3:a:gnome:tomboy:1.5.1:*:*:*:*:*:*:*

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.1

Confidence

Low

EPSS

0.001

Percentile

27.8%