Mandriva Linux Security Advisory : gnucash (MDVSA-2010:241)

medium Nessus Plugin ID 50820

Language:

Synopsis

The remote Mandriva Linux host is missing one or more security updates.

Description

A vulnerability was discovered and corrected in gnucash :

gnc-test-env in GnuCash 2.3.15 and earlier places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory (CVE-2010-3999).

The affected /usr/bin/gnc-test-env file has been removed to mitigate the CVE-2010-3999 vulnerability as gnc-test-env is only used for tests and while building gnucash.

Additionally for Mandriva 2010.1 gnucash-2.2.9 was not compatible with guile. This update adapts gnucash to the new API of guile.

Solution

Update the affected packages.

Plugin Details

Severity: Medium

ID: 50820

File Name: mandriva_MDVSA-2010-241.nasl

Version: 1.13

Type: local

Published: 11/28/2010

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6.9

Temporal Score: 5.1

Vector: CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:gnucash, p-cpe:/a:mandriva:linux:gnucash-hbci, p-cpe:/a:mandriva:linux:gnucash-ofx, p-cpe:/a:mandriva:linux:gnucash-sql, p-cpe:/a:mandriva:linux:lib64gnucash-devel, p-cpe:/a:mandriva:linux:lib64gnucash0, p-cpe:/a:mandriva:linux:libgnucash-devel, p-cpe:/a:mandriva:linux:libgnucash0, cpe:/o:mandriva:linux:2010.0, cpe:/o:mandriva:linux:2010.1

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 11/24/2010

Reference Information

CVE: CVE-2010-3999

BID: 44563

MDVSA: 2010:241