Candidate: CVE-2010-4000 PublicDate: 2010-11-06 00:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4000 Description: gnome-shell in GNOME Shell 2.31.5 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. Ubuntu-Description: Notes: Bugs: https://bugs.launchpad.net/ubuntu/+source/gnome-shell/+bug/930854 Priority: low Discovered-by: Assigned-to: CVSS: Patches_gnome-shell: upstream_gnome-shell: needs-triage dapper_gnome-shell: DNE hardy_gnome-shell: DNE karmic_gnome-shell: ignored (reached end-of-life) lucid_gnome-shell: ignored (reached end-of-life) maverick_gnome-shell: ignored (reached end-of-life) natty_gnome-shell: DNE oneiric_gnome-shell: not-affected (3.0.2-1) precise_gnome-shell: not-affected (3.0.2-1) quantal_gnome-shell: not-affected (3.0.2-1) raring_gnome-shell: not-affected (3.0.2-1) saucy_gnome-shell: not-affected (3.0.2-1) devel_gnome-shell: not-affected (3.0.2-1)