Multiple untrusted search path vulnerabilities in SUSE Linux 9.3 and 10.0, and possibly other distributions, cause the working directory to be added to LD_LIBRARY_PATH, which might allow local users to execute arbitrary code via (1) beagle, (2) tomboy, or (3) blam. NOTE: in August 2007, the tomboy vector was reported for other distributions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Suse_linux | Novell | 10.0 (including) | 10.0 (including) |
Suse_linux | Suse | 9.3 (including) | 9.3 (including) |
Tomboy | Ubuntu | dapper | * |
Tomboy | Ubuntu | edgy | * |
Tomboy | Ubuntu | feisty | * |
Tomboy | Ubuntu | gutsy | * |
Tomboy | Ubuntu | upstream | * |