Candidate: CVE-2010-3382 PublicDate: 2010-10-20 18:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3382 Description: tauex in Tuning and Analysis Utilities (TAU) 2.16.4 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_tau: upstream_tau: released (2.16.4-1.4) dapper_tau: ignored (reached end-of-life) hardy_tau: ignored (reached end-of-life) jaunty_tau: ignored (reached end-of-life) karmic_tau: ignored (reached end-of-life) lucid_tau: ignored (reached end-of-life) maverick_tau: ignored (reached end-of-life) natty_tau: not-affected (2.16.4-1.4) oneiric_tau: not-affected (2.16.4-1.4) precise_tau: not-affected (2.16.4-1.4) quantal_tau: not-affected (2.16.4-1.4) raring_tau: not-affected (2.16.4-1.4) saucy_tau: not-affected (2.16.4-1.4) devel_tau: not-affected (2.16.4-1.4)