Candidate: CVE-2010-3381 PublicDate: 2010-10-20 18:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3381 Description: The (1) tangerine and (2) tangerine-properties scripts in Tangerine 0.3.2.2 place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_tangerine: upstream_tangerine: released (0.3.4) dapper_tangerine: DNE hardy_tangerine: DNE jaunty_tangerine: ignored (reached end-of-life) karmic_tangerine: ignored (reached end-of-life) lucid_tangerine: ignored (reached end-of-life) maverick_tangerine: ignored (reached end-of-life) natty_tangerine: ignored (reached end-of-life) oneiric_tangerine: ignored (reached end-of-life) precise_tangerine: not-affected (0.3.2.2-6) quantal_tangerine: ignored (reached end-of-life) raring_tangerine: ignored (reached end-of-life) saucy_tangerine: ignored (reached end-of-life) trusty_tangerine: not-affected (0.3.2.2-6) trusty/esm_tangerine: DNE (trusty was not-affected [0.3.2.2-6]) devel_tangerine: not-affected (0.3.2.2-6)