[CVE-2005-4790] tomboy has an untrusted search path

Bug #162520 reported by Stephan Rügamer
266
Affects Status Importance Assigned to Milestone
tomboy (Ubuntu)
Fix Released
Undecided
Stephan Rügamer
Dapper
Fix Released
Low
Unassigned
Edgy
Fix Released
Low
Unassigned
Feisty
Fix Released
Low
Unassigned
Gutsy
Fix Released
Low
Unassigned

Bug Description

Binary package hint: tomboy

Dear Colleagues,

tomboy has some untrusted search paths.

CVE says:

Multiple untrusted search path vulnerabilities in SUSE Linux 9.3 and 10.0, and possibly other distributions, cause the working directory to be added to LD_LIBRARY_PATH, which might allow local users to execute arbitrary code via (1) beagle, (2) tomboy, or (3) blam. NOTE: in August 2007, the tomboy vector was reported for other distributions.

PLease find attached debdiffs for all supported releases.

Regards,

\sh

CVE References

Revision history for this message
Stephan Rügamer (sruegamer) wrote :
Revision history for this message
Stephan Rügamer (sruegamer) wrote :
Revision history for this message
Stephan Rügamer (sruegamer) wrote :
Revision history for this message
Stephan Rügamer (sruegamer) wrote :
Changed in tomboy:
assignee: nobody → shermann
status: New → In Progress
Kees Cook (kees)
Changed in tomboy:
importance: Undecided → Low
status: New → In Progress
importance: Undecided → Low
status: New → In Progress
importance: Undecided → Low
status: New → In Progress
importance: Undecided → Low
status: New → In Progress
Revision history for this message
Jamie Strandboge (jdstrand) wrote :
Changed in tomboy:
status: In Progress → Fix Released
status: In Progress → Fix Released
status: In Progress → Fix Released
status: In Progress → Fix Released
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Closing bug. Hardy not affected (0.9.1-0ubuntu1)

Changed in tomboy:
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.