VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-3372
nordugrid-arc: Untrusted search path vulnerability in NorduGrid Ad...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-3372

Original

Untrusted search path vulnerability in NorduGrid Advanced Resource Connector (ARC) before 0.8.3 allows local users to gain privileges via vectors related to the LD_LIBRARY_PATH environment variable. NOTE: some of these details are obtained from third party information.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-12-08
Source Information Category:
Advisory, Alert
Last Updated:
2010-12-09




Affected Product Tags
cpe:/a:nordugrid:nordugrid-arc:0.3.22
cpe:/a:nordugrid:nordugrid-arc:0.3.23
cpe:/a:nordugrid:nordugrid-arc:0.3.24
cpe:/a:nordugrid:nordugrid-arc:0.3.25
cpe:/a:nordugrid:nordugrid-arc:0.3.26
cpe:/a:nordugrid:nordugrid-arc:0.3.27
cpe:/a:nordugrid:nordugrid-arc:0.3.28
cpe:/a:nordugrid:nordugrid-arc:0.3.29
cpe:/a:nordugrid:nordugrid-arc:0.3.30
cpe:/a:nordugrid:nordugrid-arc:0.3.31
cpe:/a:nordugrid:nordugrid-arc:0.3.32
cpe:/a:nordugrid:nordugrid-arc:0.3.33
cpe:/a:nordugrid:nordugrid-arc:0.3.34
cpe:/a:nordugrid:nordugrid-arc:0.3.35
cpe:/a:nordugrid:nordugrid-arc:0.3.36
cpe:/a:nordugrid:nordugrid-arc:0.3.37
cpe:/a:nordugrid:nordugrid-arc:0.3.38
cpe:/a:nordugrid:nordugrid-arc:0.3.39
cpe:/a:nordugrid:nordugrid-arc:0.3.40
cpe:/a:nordugrid:nordugrid-arc:0.4.0
cpe:/a:nordugrid:nordugrid-arc:0.4.1
cpe:/a:nordugrid:nordugrid-arc:0.4.2
cpe:/a:nordugrid:nordugrid-arc:0.4.3
cpe:/a:nordugrid:nordugrid-arc:0.4.4
cpe:/a:nordugrid:nordugrid-arc:0.4.5
cpe:/a:nordugrid:nordugrid-arc:0.5.0
cpe:/a:nordugrid:nordugrid-arc:0.5.1
cpe:/a:nordugrid:nordugrid-arc:0.5.10
cpe:/a:nordugrid:nordugrid-arc:0.5.11
cpe:/a:nordugrid:nordugrid-arc:0.5.12
cpe:/a:nordugrid:nordugrid-arc:0.5.13
cpe:/a:nordugrid:nordugrid-arc:0.5.14
cpe:/a:nordugrid:nordugrid-arc:0.5.15
cpe:/a:nordugrid:nordugrid-arc:0.5.16
cpe:/a:nordugrid:nordugrid-arc:0.5.17
cpe:/a:nordugrid:nordugrid-arc:0.5.18
cpe:/a:nordugrid:nordugrid-arc:0.5.19
cpe:/a:nordugrid:nordugrid-arc:0.5.2
cpe:/a:nordugrid:nordugrid-arc:0.5.20
cpe:/a:nordugrid:nordugrid-arc:0.5.21
cpe:/a:nordugrid:nordugrid-arc:0.5.22
cpe:/a:nordugrid:nordugrid-arc:0.5.23
cpe:/a:nordugrid:nordugrid-arc:0.5.24
cpe:/a:nordugrid:nordugrid-arc:0.5.25
cpe:/a:nordugrid:nordugrid-arc:0.5.26
cpe:/a:nordugrid:nordugrid-arc:0.5.27
cpe:/a:nordugrid:nordugrid-arc:0.5.28
cpe:/a:nordugrid:nordugrid-arc:0.5.29
cpe:/a:nordugrid:nordugrid-arc:0.5.3
cpe:/a:nordugrid:nordugrid-arc:0.5.30
cpe:/a:nordugrid:nordugrid-arc:0.5.31
cpe:/a:nordugrid:nordugrid-arc:0.5.32
cpe:/a:nordugrid:nordugrid-arc:0.5.33
cpe:/a:nordugrid:nordugrid-arc:0.5.34
cpe:/a:nordugrid:nordugrid-arc:0.5.35
cpe:/a:nordugrid:nordugrid-arc:0.5.36
cpe:/a:nordugrid:nordugrid-arc:0.5.37
cpe:/a:nordugrid:nordugrid-arc:0.5.38
cpe:/a:nordugrid:nordugrid-arc:0.5.39
cpe:/a:nordugrid:nordugrid-arc:0.5.4
cpe:/a:nordugrid:nordugrid-arc:0.5.40
cpe:/a:nordugrid:nordugrid-arc:0.5.41
cpe:/a:nordugrid:nordugrid-arc:0.5.42
cpe:/a:nordugrid:nordugrid-arc:0.5.43
cpe:/a:nordugrid:nordugrid-arc:0.5.44
cpe:/a:nordugrid:nordugrid-arc:0.5.45
cpe:/a:nordugrid:nordugrid-arc:0.5.46
cpe:/a:nordugrid:nordugrid-arc:0.5.47
cpe:/a:nordugrid:nordugrid-arc:0.5.48
cpe:/a:nordugrid:nordugrid-arc:0.5.49
cpe:/a:nordugrid:nordugrid-arc:0.5.5
cpe:/a:nordugrid:nordugrid-arc:0.5.50
cpe:/a:nordugrid:nordugrid-arc:0.5.51
cpe:/a:nordugrid:nordugrid-arc:0.5.52
cpe:/a:nordugrid:nordugrid-arc:0.5.53
cpe:/a:nordugrid:nordugrid-arc:0.5.54
cpe:/a:nordugrid:nordugrid-arc:0.5.55
cpe:/a:nordugrid:nordugrid-arc:0.5.56
cpe:/a:nordugrid:nordugrid-arc:0.5.57
cpe:/a:nordugrid:nordugrid-arc:0.5.58
cpe:/a:nordugrid:nordugrid-arc:0.5.6
cpe:/a:nordugrid:nordugrid-arc:0.5.7
cpe:/a:nordugrid:nordugrid-arc:0.5.8
cpe:/a:nordugrid:nordugrid-arc:0.5.9
cpe:/a:nordugrid:nordugrid-arc:0.6.0
cpe:/a:nordugrid:nordugrid-arc:0.6.1
cpe:/a:nordugrid:nordugrid-arc:0.6.2
cpe:/a:nordugrid:nordugrid-arc:0.6.3
cpe:/a:nordugrid:nordugrid-arc:0.6.4
cpe:/a:nordugrid:nordugrid-arc:0.6.5
cpe:/a:nordugrid:nordugrid-arc:0.8.1
cpe:/a:nordugrid:nordugrid-arc:0.8.1.1
cpe:/a:nordugrid:nordugrid-arc:0.8.1.1-1
cpe:/a:nordugrid:nordugrid-arc:0.8.1.1-2
cpe:/a:nordugrid:nordugrid-arc:0.8.2 and previous versions
cpe:/a:nordugrid:nordugrid-arc:0.8.2.1
cpe:/a:nordugrid:nordugrid-arc:0.8.2.2
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

X Local [?]
Adjacent Network [?]
Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
X Medium [?]
Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

[Availability Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

Alternatives




References
CONFIRM http://www.nordugrid.org/arc/releases/0_8_3/release_notes_0_8_3.html




SECUNIA 42496




Vulnerability Type Other (NVD-CWE-Other)





Copyright © 2010 JPCERT/CC All Rights Reserved.