CVE Vulnerabilities

CVE-2005-0627

Published: May 02, 2005 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Qt before 3.3.4 searches the BUILD_PREFIX directory, which could be world-writable, to load shared libraries regardless of the LD_LIBRARY_PATH environment variable, which allows local users to execute arbitrary programs.

Affected Software

Name Vendor Start Version End Version
Qt Trolltech 3.0 (including) 3.0 (including)
Qt Trolltech 3.0.3 (including) 3.0.3 (including)
Qt Trolltech 3.0.5 (including) 3.0.5 (including)
Qt Trolltech 3.1 (including) 3.1 (including)
Qt Trolltech 3.1.1 (including) 3.1.1 (including)
Qt Trolltech 3.1.2 (including) 3.1.2 (including)
Qt Trolltech 3.2.1 (including) 3.2.1 (including)
Qt Trolltech 3.2.3 (including) 3.2.3 (including)
Qt Trolltech 3.3.0 (including) 3.3.0 (including)
Qt Trolltech 3.3.1 (including) 3.3.1 (including)
Qt Trolltech 3.3.2 (including) 3.3.2 (including)
Qt Trolltech 3.3.3 (including) 3.3.3 (including)

References