Vulnerability Description
Qt before 3.3.4 searches the BUILD_PREFIX directory, which could be world-writable, to load shared libraries regardless of the LD_LIBRARY_PATH environment variable, which allows local users to execute arbitrary programs.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trolltech | Qt | 3.0 |
References
- http://bugs.gentoo.org/show_bug.cgi?id=75181Patch
- http://www.gentoo.org/security/en/glsa/glsa-200503-01.xmlPatchVendor Advisory
- http://www.securityfocus.com/bid/12695Patch
- http://bugs.gentoo.org/show_bug.cgi?id=75181Patch
- http://www.gentoo.org/security/en/glsa/glsa-200503-01.xmlPatchVendor Advisory
- http://www.securityfocus.com/bid/12695Patch
FAQ
What is CVE-2005-0627?
CVE-2005-0627 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Qt before 3.3.4 searches the BUILD_PREFIX directory, which could be world-writable, to load shared libraries regardless of the LD_LIBRARY_PATH environment variable, which allows local users to execute...
How severe is CVE-2005-0627?
CVE-2005-0627 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-0627?
Check the references section above for vendor advisories and patch information. Affected products include: Trolltech Qt.