CVE-2010-4005
06.11.2010, 00:00
The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1.5.2 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: vector 1 exists because of an incorrect fix for CVE-2005-4790.2.
Vendor | Product | Version |
---|---|---|
gnome | tomboy | 𝑥 ≤ 1.5.2 |
gnome | tomboy | 1.0.1 |
gnome | tomboy | 1.2.2 |
gnome | tomboy | 1.4.2 |
gnome | tomboy | 1.5.1 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
tomboy |
|
References