PT-2008-6043 · Valgrind · Valgrind

Tavis Ormandy

·

Publicado

2008-10-31

·

Atualizado

2024-06-15

·

CVE-2008-4865

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions valgrind versions prior to 3.4.0
Description The issue allows local users to execute arbitrary programs via a Trojan horse .valgrindrc file in the current working directory. This can be achieved by using a malicious --db-command option. The severity of this issue has been disputed, but it is considered a potential risk because execution of a program from an untrusted directory is a common scenario.
Recommendations For valgrind versions prior to 3.4.0, update to version 3.4.0 or later to resolve the issue. As a temporary workaround, consider avoiding the use of untrusted directories or restricting access to the .valgrindrc file to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2008-4865
OPENSUSE-SU-2024:11492-1

Produtos afetados

Valgrind