>> Liferea "LD_LIBRARY_PATH" Variable Local Code Execution Vulnerability
Title : Liferea "LD_LIBRARY_PATH" Variable Local Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2007-3965 CVE ID : CVE-2005-4791
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2007-11-22
Technical Description
A vulnerability has been identified in Liferea, which could be exploited by local attackers to potentially obtain elevated privileges. This issue is caused by an error in the starter script that does not properly set the "LD_LIBRARY_PATH" environment variable, which could be exploited by malicious users to execute arbitrary code by tricking a user into running a vulnerable application in a directory containing a specially crafted library file.
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback If you have additional information or corrections for this security advisory please submit them via our contact form.