Untrusted Search Path Vulnerability in CouchDB by Debian
CVE-2010-2953

Currently unrated

Key Information:

Vendor

Apache

Status
Vendor
CVE Published:
14 September 2010

What is CVE-2010-2953?

A vulnerability exists in the CouchDB script provided by Debian GNU/Linux, where an untrusted search path is exploited by local users. This flaw allows attackers to gain elevated privileges by placing a malicious shared library in the current working directory, which is then executed by the script. Users of CouchDB 0.8.0 should take immediate action to mitigate the risk of unauthorized privilege escalation.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.