-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Gentoo Linux Security Advisory GLSA 200711-12
https://security.gentoo.org/
Severity: Normal
Title: Tomboy: User-assisted execution of arbitrary code
Date: November 08, 2007
Bugs: #189249
ID: 200711-12
Synopsis
=======
Tomboy doesn't properly handle environment variables, potentially
allowing a local attacker to execute arbitrary code.
Background
=========
Tomboy is a GTK-based desktop note-taking application written in C# and
the Mono C#.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 app-misc/tomboy < 0.8.1-r1 >= 0.8.1-r1
==========
Jan Oravec reported that the "/usr/bin/tomboy" script sets the
"LD_LIBRARY_PATH...Read the Full Advisory
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.