CVE-2010-3387
EPSS 0.40%
描述
vdrleaktest in Video Disk Recorder (VDR) 1.6.0 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: a third party disputes this issue because the script erroneously uses a semicolon in a context where a colon was intended
如何修補 CVE-2010-3387
要修補 CVE-2010-3387,請將受影響套件升級到下列已修補版本。
- Debian/vdr—升級至 1.6.0-19.1 或更新版本
CVE-2010-3387 正在被利用嗎?
低 — EPSS 為 0.4%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 1.6.0-19.1