Candidate: CVE-2010-2945 PublicDate: 2010-08-30 20:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2945 Description: The default configuration of SLiM before 1.3.2 places ./ (dot slash) at the beginning of the default_path option, which might allow local users to gain privileges via a Trojan horse program in the current working directory, related to slim.conf and cfg.cpp. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_slim: upstream_slim: released (1.3.1-7) dapper_slim: DNE hardy_slim: ignored (reached end-of-life) jaunty_slim: ignored (reached end-of-life) karmic_slim: DNE lucid_slim: ignored (reached end-of-life) maverick_slim: not-affected (1.3.1-7) natty_slim: not-affected (1.3.1-7) oneiric_slim: not-affected (1.3.1-7) precise_slim: not-affected (1.3.1-7) quantal_slim: not-affected (1.3.1-7) raring_slim: not-affected (1.3.1-7) saucy_slim: not-affected (1.3.1-7) devel_slim: not-affected (1.3.1-7)