Vulnerability Description
monero-wallet-gui in Monero GUI before 0.17.1.0 includes the . directory in an embedded RPATH (with a preference ahead of /usr/lib), which allows local users to gain privileges via a Trojan horse library in the current working directory.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Getmonero | Monero | < 0.17.1.0 |
Related Weaknesses (CWE)
References
- https://github.com/monero-project/monero-gui/commit/6ed536982953d870010d8fa065dcPatchThird Party Advisory
- https://github.com/monero-project/monero-gui/issues/3142#issuecomment-705940446Third Party Advisory
- https://github.com/monero-project/monero-gui/commit/6ed536982953d870010d8fa065dcPatchThird Party Advisory
- https://github.com/monero-project/monero-gui/issues/3142#issuecomment-705940446Third Party Advisory
FAQ
What is CVE-2020-26947?
CVE-2020-26947 is a vulnerability with a CVSS score of 7.8 (HIGH). monero-wallet-gui in Monero GUI before 0.17.1.0 includes the . directory in an embedded RPATH (with a preference ahead of /usr/lib), which allows local users to gain privileges via a Trojan horse libr...
How severe is CVE-2020-26947?
CVE-2020-26947 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-26947?
Check the references section above for vendor advisories and patch information. Affected products include: Getmonero Monero.