Back

MEDIUM

Server: use of insecure LD_LIBRARY_PATH settings

Published Feb 23, 2011

Description

The (1) backup and restore scripts, (2) main initialization script, and (3) ldap-agent script in 389 Directory Server 1.2.x (aka Red Hat Directory Server 8.2.x) place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 23, 2011
Updated Aug 6, 2024
Reserved Jan 20, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Feb 22, 2011