CVE-2010-3385

Publication date 20 October 2010

Last updated 24 July 2024


Ubuntu priority

Description

TuxGuitar 1.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

Status

Package Ubuntu Release Status
tuxguitar 11.10 oneiric
Not affected
11.04 natty
Not affected
10.10 maverick
Fixed 1.2-6ubuntu1.1
10.04 LTS lucid
Fixed 1.1-1ubuntu4.1
9.10 karmic Ignored end of life
9.04 jaunty Ignored end of life
8.04 LTS hardy Ignored end of life
6.06 LTS dapper Not in release


Access our resources on patching vulnerabilities