Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-3381
HistoryAug 17, 2012 - 12:00 a.m.

CVE-2012-3381

2012-08-1700:00:00
ubuntu.com
ubuntu.com
12

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

5.1%

sfcb in sblim-sfcb places a zero-length directory name in the
LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan
horse shared library in the current working directory.

Notes

Author Note
sbeattie debian/ubuntu not affected because upstream init scripts are not used; debian init script does not contain LD_LIBRARY_PATH usage

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

5.1%

Related for UB:CVE-2012-3381