Unrated severityNVD Advisory· Published Nov 1, 2008· Updated Apr 23, 2026
CVE-2008-4865
CVE-2008-4865
Description
Untrusted search path vulnerability in valgrind before 3.4.0 allows local users to execute arbitrary programs via a Trojan horse .valgrindrc file in the current working directory, as demonstrated using a malicious --db-command options. NOTE: the severity of this issue has been disputed, but CVE is including this issue because execution of a program from an untrusted directory is a common scenario.
Affected products
22cpe:2.3:a:valgrind:valgrind:*:rc1:*:*:*:*:*:*+ 21 more
- cpe:2.3:a:valgrind:valgrind:*:rc1:*:*:*:*:*:*range: <=3.4.0
- cpe:2.3:a:valgrind:valgrind:1.9.6:*:*:*:*:*:*:*
- cpe:2.3:a:valgrind:valgrind:2.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:valgrind:valgrind:2.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:valgrind:valgrind:2.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:valgrind:valgrind:2.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:valgrind:valgrind:2.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:valgrind:valgrind:2.4.1:*:powerpc:*:*:*:*:*
- cpe:2.3:a:valgrind:valgrind:3.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:valgrind:valgrind:3.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:valgrind:valgrind:3.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:valgrind:valgrind:3.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:valgrind:valgrind:3.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:valgrind:valgrind:3.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:valgrind:valgrind:3.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:valgrind:valgrind:3.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:valgrind:valgrind:3.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:valgrind:valgrind:3.3.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:valgrind:valgrind:3.3.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:valgrind:valgrind:3.3.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:valgrind:valgrind:3.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:valgrind:valgrind:3.3.1:rc1:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- secunia.com/advisories/33568nvdVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.htmlnvd
- security.gentoo.org/glsa/glsa-200902-03.xmlnvd
- sourceforge.net/mailarchive/forum.phpnvd
- www.openwall.com/lists/oss-security/2008/10/27/4nvd
- www.openwall.com/lists/oss-security/2008/10/28/5nvd
- www.openwall.com/lists/oss-security/2008/10/29/5nvd
- www.openwall.com/lists/oss-security/2008/10/29/9nvd
News mentions
0No linked articles in our index yet.