Candidate: CVE-2010-2953 PublicDate: 2010-09-14 19:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2953 Description: Untrusted search path vulnerability in a certain Debian GNU/Linux patch for the couchdb script in CouchDB 0.8.0 allows local users to gain privileges via a crafted shared library in the current working directory. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=594412 Priority: low Discovered-by: Assigned-to: CVSS: Patches_couchdb: upstream_couchdb: not-affected (patch not upstream) dapper_couchdb: DNE hardy_couchdb: DNE jaunty_couchdb: ignored (reached end-of-life) karmic_couchdb: ignored (reached end-of-life) lucid_couchdb: ignored (reached end-of-life) maverick_couchdb: released (1.0.1-0ubuntu2) natty_couchdb: released (1.0.1-0ubuntu2) oneiric_couchdb: released (1.0.1-0ubuntu2) precise_couchdb: released (1.0.1-0ubuntu2) quantal_couchdb: released (1.0.1-0ubuntu2) raring_couchdb: released (1.0.1-0ubuntu2) devel_couchdb: released (1.0.1-0ubuntu2)