Lucene search

K
jvnJapan Vulnerability NotesJVN:50610528
HistoryOct 22, 2010 - 12:00 a.m.

JVN#50610528: Sleipnir and Grani may insecurely load dynamic libraries

2010-10-2200:00:00
Japan Vulnerability Notes
jvn.jp
21

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

EPSS

0

Percentile

5.1%

Sleipnir and Grani provided by Fenrir are web browsers. Sleipnir and Grani loads certain DLL’s when HTML files are opened. Sleipnir and Grani contain an issue with the DLL search path, which may lead to insecurely loading dynamic libraries.

Impact

An attacker may execute arbitrary code with the privilege of running the application.

Solution

Update the Software
Update to the latest version according to the information provided by the developer.

Products Affected

  • Sleipnir 2.9.4 and earlier
  • Grani 4.3 and earlier

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

EPSS

0

Percentile

5.1%

Related for JVN:50610528