CVE Vulnerabilities

CVE-2010-3383

Published: Oct 20, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The (1) teamspeak and (2) teamspeak-server scripts in TeamSpeak 2.0.32 place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

Affected Software

NameVendorStart VersionEnd Version
TeamspeakTeamspeak2.0.32 (including)2.0.32 (including)
Teamspeak-clientUbuntuhardy*
Teamspeak-clientUbuntujaunty*
Teamspeak-clientUbuntukarmic*
Teamspeak-clientUbuntulucid*
Teamspeak-clientUbuntumaverick*
Teamspeak-clientUbuntunatty*
Teamspeak-clientUbuntuoneiric*
Teamspeak-clientUbuntuprecise*
Teamspeak-clientUbuntuquantal*
Teamspeak-clientUbunturaring*
Teamspeak-clientUbuntusaucy*
Teamspeak-serverUbuntuhardy*
Teamspeak-serverUbuntujaunty*
Teamspeak-serverUbuntukarmic*
Teamspeak-serverUbuntulucid*
Teamspeak-serverUbuntumaverick*
Teamspeak-serverUbuntunatty*
Teamspeak-serverUbuntuoneiric*
Teamspeak-serverUbuntuquantal*
Teamspeak-serverUbunturaring*
Teamspeak-serverUbuntusaucy*
Teamspeak-serverUbuntuupstream*

References