CVE-2010-3350

Publication date 20 October 2010

Last updated 24 July 2024


Ubuntu priority

bareFTP 0.3.4 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
bareftp 10.10 maverick
Fixed 0.3.4-1ubuntu0.1
10.04 LTS lucid
Fixed 0.3.1-1ubuntu1.2
9.10 karmic Not in release
9.04 jaunty Not in release
8.04 LTS hardy Not in release
6.06 LTS dapper Not in release