CVE-2008-3277

Publication date 15 April 2014

Last updated 24 July 2024


Ubuntu priority

Description

Untrusted search path vulnerability in a certain Red Hat build script for the ibmssh executable in ibutils packages before ibutils-1.5.7-2.el6 in Red Hat Enterprise Linux (RHEL) 6 and ibutils-1.2-11.2.el5 in Red Hat Enterprise Linux (RHEL) 5 allows local users to gain privileges via a Trojan Horse program in refix/lib/, related to an incorrect RPATH setting in the ELF header.

Read the notes from the security team

Status

Package Ubuntu Release Status
ibutils 11.10 oneiric
Not affected
11.04 natty
Not affected
10.10 maverick Not in release
10.04 LTS lucid Not in release
8.04 LTS hardy Not in release

Notes


tyhicks

ibmssh not built in natty-precise


Access our resources on patching vulnerabilities