CVE-2010-3389

The (1) SAPDatabase and (2) SAPInstance scripts in OCF Resource Agents (aka resource-agents or cluster-agents) 1.0.3 in Linux-HA place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:linux-ha:ocf_resource_agents:1.0.3:*:*:*:*:*:*:*

Information

Published : 2010-10-20 11:00

Updated : 2012-02-01 19:58


NVD link : CVE-2010-3389

Mitre link : CVE-2010-3389


JSON object : View

Advertisement

dedicated server usa

Products Affected

linux-ha

  • ocf_resource_agents