PT-2005-5454 · Suse · Suse Linux
Published
2005-12-31
·
Updated
2024-06-15
·
CVE-2005-4791
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
SUSE Linux version 10.0
Description
The issue is related to multiple untrusted search path vulnerabilities. These vulnerabilities cause the working directory to be added to LD LIBRARY PATH, which might allow local users to execute arbitrary code. This can be achieved via certain applications.
Recommendations
For SUSE Linux version 10.0, consider restricting access to sensitive directories and limiting the use of potentially vulnerable applications until a fix is available. As a temporary workaround, avoid using applications such as liferea or banshee in untrusted environments to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Suse Linux