CVE Vulnerabilities

CVE-2008-4865

Published: Nov 01, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
3.7 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Untrusted search path vulnerability in valgrind before 3.4.0 allows local users to execute arbitrary programs via a Trojan horse .valgrindrc file in the current working directory, as demonstrated using a malicious –db-command options. NOTE: the severity of this issue has been disputed, but CVE is including this issue because execution of a program from an untrusted directory is a common scenario.

Affected Software

NameVendorStart VersionEnd Version
ValgrindValgrind*3.4.0 (including)
ValgrindValgrind1.9.6 (including)1.9.6 (including)
ValgrindValgrind2.0.0 (including)2.0.0 (including)
ValgrindValgrind2.1.0 (including)2.1.0 (including)
ValgrindValgrind2.1.1 (including)2.1.1 (including)
ValgrindValgrind2.2.0 (including)2.2.0 (including)
ValgrindValgrind2.4.1 (including)2.4.1 (including)
ValgrindValgrind3.0.0 (including)3.0.0 (including)
ValgrindValgrind3.0.1 (including)3.0.1 (including)
ValgrindValgrind3.1.0 (including)3.1.0 (including)
ValgrindValgrind3.1.1 (including)3.1.1 (including)
ValgrindValgrind3.2.0 (including)3.2.0 (including)
ValgrindValgrind3.2.1 (including)3.2.1 (including)
ValgrindValgrind3.2.2 (including)3.2.2 (including)
ValgrindValgrind3.2.3 (including)3.2.3 (including)
ValgrindValgrind3.3.0 (including)3.3.0 (including)
ValgrindValgrind3.3.0-rc1 (including)3.3.0-rc1 (including)
ValgrindValgrind3.3.0-rc2 (including)3.3.0-rc2 (including)
ValgrindValgrind3.3.0-rc3 (including)3.3.0-rc3 (including)
ValgrindValgrind3.3.1 (including)3.3.1 (including)
ValgrindValgrind3.3.1-rc1 (including)3.3.1-rc1 (including)
Red Hat Enterprise Linux 5RedHatvalgrind-1:3.5.0-1.el5*
ValgrindUbuntudapper*
ValgrindUbuntugutsy*
ValgrindUbuntuhardy*
ValgrindUbuntuintrepid*
ValgrindUbuntuupstream*

References