PT-2008-6043 · Valgrind · Valgrind
Tavis Ormandy
·
Publicado
2008-10-31
·
Atualizado
2024-06-15
·
CVE-2008-4865
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
valgrind versions prior to 3.4.0
Description
The issue allows local users to execute arbitrary programs via a Trojan horse .valgrindrc file in the current working directory. This can be achieved by using a malicious
--db-command option. The severity of this issue has been disputed, but it is considered a potential risk because execution of a program from an untrusted directory is a common scenario.Recommendations
For valgrind versions prior to 3.4.0, update to version 3.4.0 or later to resolve the issue. As a temporary workaround, consider avoiding the use of untrusted directories or restricting access to the .valgrindrc file to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Valgrind