Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Gentoo: GLSA-200711-12 Normal: Tomboy Code Execution Risk

gentoo
Calendar Grey November 8, 2007
Scroller Gentoo
A recent Gentoo advisory reveals a vulnerability in Tomboy allowing unauthorized code execution via altered environment variables. Update your software for security
Tomboy doesn't properly handle environment variables, potentially allowing a local attacker to execute arbitrary code.

Summary

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Gentoo Linux Security Advisory                           GLSA 200711-12
                                            https://security.gentoo.org/

Severity: Normal Title: Tomboy: User-assisted execution of arbitrary code Date: November 08, 2007 Bugs: #189249 ID: 200711-12

Synopsis ======= Tomboy doesn't properly handle environment variables, potentially allowing a local attacker to execute arbitrary code.
Background ========= Tomboy is a GTK-based desktop note-taking application written in C# and the Mono C#.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-misc/tomboy < 0.8.1-r1 >= 0.8.1-r1
========== Jan Oravec reported that the "/usr/bin/tomboy" script sets the "LD_LIBRARY_PATH...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround