bareFTP 0.3.4 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
References
Configurations
Information
Published : 2010-10-20 11:00
Updated : 2017-08-16 18:32
NVD link : CVE-2010-3350
Mitre link : CVE-2010-3350
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
bareftp
- bareftp