PT-2008-6043 · Valgrind · Valgrind

Tavis Ormandy

·

Published

2008-10-31

·

Updated

2024-06-15

·

CVE-2008-4865

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions valgrind versions prior to 3.4.0
Description The issue allows local users to execute arbitrary programs via a Trojan horse .valgrindrc file in the current working directory. This can be achieved by using a malicious --db-command option. The severity of this issue has been disputed, but it is considered a potential risk because execution of a program from an untrusted directory is a common scenario.
Recommendations For valgrind versions prior to 3.4.0, update to version 3.4.0 or later to resolve the issue. As a temporary workaround, consider avoiding the use of untrusted directories or restricting access to the .valgrindrc file to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2008-4865
OPENSUSE-SU-2024:11492-1

Affected Products

Valgrind