Vulnerabilities > CVE-2010-2953 - Remote Code Execution vulnerability in Apache Couchdb 0.8.0

047910
CVSS 6.9 - MEDIUM
Attack vector
LOCAL
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
apache
nessus

Summary

Untrusted search path vulnerability in a certain Debian GNU/Linux patch for the couchdb script in CouchDB 0.8.0 allows local users to gain privileges via a crafted shared library in the current working directory. Per: http://cwe.mitre.org/data/definitions/426.html 'CWE-426: Untrusted Search Path'

Vulnerable Configurations

Part Description Count
Application
Apache
1

Nessus

  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2010-13640.NASL
    descriptionDespite the fact that this is a security-related fix I would like to test these packages for a while because of possible API incompatibilities (version upgrade). Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id49293
    published2010-09-21
    reporterThis script is Copyright (C) 2010-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/49293
    titleFedora 13 : couchdb-0.11.2-2.fc13 (2010-13640)
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-2107.NASL
    descriptionDan Rosenberg discovered that in couchdb, a distributed, fault-tolerant and schema-free document-oriented database, an insecure library search path is used. A local attacker could execute arbitrary code by first dumping a maliciously crafted shared library in some directory, and then having an administrator run couchdb from this same directory.
    last seen2020-06-01
    modified2020-06-02
    plugin id49184
    published2010-09-12
    reporterThis script is Copyright (C) 2010-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/49184
    titleDebian DSA-2107-1 : couchdb - untrusted search path
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2010-13665.NASL
    descriptionDespite the fact that this is a security-related fix I would like to test these packages for a while because of possible API incompatibilities (version upgrade). Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id49294
    published2010-09-21
    reporterThis script is Copyright (C) 2010-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/49294
    titleFedora 12 : couchdb-0.11.2-2.fc12 (2010-13665)