CVE Vulnerabilities

CVE-2010-4001

Published: Nov 06, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

GMXRC.bash in Gromacs 4.5.1 and earlier places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: CVE disputes this issue because the GMXLDLIB value is always added to the beginning of LD_LIBRARY_PATH at a later point in the script

Affected Software

NameVendorStart VersionEnd Version
GromacsGromacs*4.5.1 (including)
GromacsUbuntuartful*
GromacsUbuntubionic*
GromacsUbuntucosmic*
GromacsUbuntudapper*
GromacsUbuntudisco*
GromacsUbuntueoan*
GromacsUbuntugroovy*
GromacsUbuntuhardy*
GromacsUbuntuhirsute*
GromacsUbuntuimpish*
GromacsUbuntukarmic*
GromacsUbuntukinetic*
GromacsUbuntulucid*
GromacsUbuntulunar*
GromacsUbuntumantic*
GromacsUbuntumaverick*
GromacsUbuntunatty*
GromacsUbuntuoneiric*
GromacsUbuntuprecise*
GromacsUbuntuquantal*
GromacsUbunturaring*
GromacsUbuntusaucy*
GromacsUbuntutrusty*
GromacsUbuntuutopic*
GromacsUbuntuvivid*
GromacsUbuntuwily*
GromacsUbuntuxenial*
GromacsUbuntuyakkety*
GromacsUbuntuzesty*

References