gnc-test-env in GnuCash 2.3.15 and earlier places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gnucash | Jul 30, 2024 | Nov 5, 2010 |
| Gentoo Linux | — | Upgrade media-sound/lastfmplayer.Upgrade net-analyzer/sflowtool.Upgrade app-admin/syslog-ng.Upgrade sys-cluster/resource-agents.Upgrade games-sports/racer-bin.Upgrade dev-libs/xmlsec.Upgrade app-misc/ca-certificates.Upgrade dev-util/qt-creator.Upgrade dev-util/oprofile.Upgrade dev-vcs/gitolite.Upgrade sys-fs/lvm2.Upgrade dev-db/unixODBC.Upgrade net-libs/webkit-gtk.Upgrade app-office/gnucash.Upgrade media-libs/fmod.Upgrade dev-php/PEAR-PEAR.Upgrade net-misc/vino.Upgrade net-misc/mrouted.Upgrade net-libs/libsoup.Upgrade net-misc/rsync.Upgrade x11-apps/xrdb.Upgrade dev-php/PEAR-Mail.Upgrade gnome-base/gdm.Upgrade sys-apps/shadow.Upgrade media-libs/xine-lib. | Oct 30, 2017 | Nov 5, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub