| ID |
CVE-2010-3369
|
| Sažetak |
The (1) mdb and (2) mdb-symbolreader scripts in mono-debugger 2.4.3, and other versions before 2.8.1, place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. |
| Reference |
|
| CVSS |
| Base: | 6.9 |
| Impact: | 10.0 |
| Exploitability: | 3.4 |
|
| Pristup |
| Vektor | Složenost | Autentikacija |
| LOCAL |
MEDIUM |
NONE |
|
| Impact |
| Povjerljivost | Cjelovitost | Dostupnost |
| COMPLETE |
COMPLETE |
COMPLETE |
|
| CVSS vektor |
AV:L/AC:M/Au:N/C:C/I:C/A:C |
| Zadnje važnije ažuriranje |
14-12-2010 - 05:00 |
| Objavljeno |
20-10-2010 - 18:00 |