Vulnerabilities > CVE-2010-3349 - Unspecified vulnerability in Ardour 2.8.11

047910
CVSS 6.9 - MEDIUM
Attack vector
LOCAL
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
ardour
nessus

Summary

Ardour 2.8.11 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

Vulnerable Configurations

Part Description Count
Application
Ardour
1

Nessus

  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2010-15560.NASL
    descriptionFix CVE-2010-3349 - insecure library loading vulnerability Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id49982
    published2010-10-15
    reporterThis script is Copyright (C) 2010-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/49982
    titleFedora 14 : ardour-2.8.11-5.fc14 (2010-15560)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2010-15510.NASL
    descriptionFix CVE-2010-3349 - insecure library loading vulnerability Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id49981
    published2010-10-15
    reporterThis script is Copyright (C) 2010-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/49981
    titleFedora 13 : ardour-2.8.11-5.fc13 (2010-15510)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2010-15499.NASL
    descriptionFix CVE-2010-3349 - insecure library loading vulnerability Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id49980
    published2010-10-15
    reporterThis script is Copyright (C) 2010-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/49980
    titleFedora 12 : ardour-2.8.11-5.fc12 (2010-15499)