Unrated severityNVD Advisory· Published Oct 4, 2010· Updated Apr 29, 2026
CVE-2010-3374
CVE-2010-3374
Description
Qt Creator before 2.0.1 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Affected products
15cpe:2.3:a:nokia:qt_creator:*:*:*:*:*:*:*:*+ 14 more
- cpe:2.3:a:nokia:qt_creator:*:*:*:*:*:*:*:*range: <=2.0.0
- cpe:2.3:a:nokia:qt_creator:0.9.1:beta:*:*:*:*:*:*
- cpe:2.3:a:nokia:qt_creator:0.9.2:rc1:*:*:*:*:*:*
- cpe:2.3:a:nokia:qt_creator:1.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:nokia:qt_creator:1.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:nokia:qt_creator:1.1.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:nokia:qt_creator:1.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:nokia:qt_creator:1.2.90:*:*:*:*:*:*:*
- cpe:2.3:a:nokia:qt_creator:1.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:nokia:qt_creator:1.3.0:beta:*:*:*:*:*:*
- cpe:2.3:a:nokia:qt_creator:1.3.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:nokia:qt_creator:1.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:nokia:qt_creator:2.0.0:alpha:*:*:*:*:*:*
- cpe:2.3:a:nokia:qt_creator:2.0.0:beta:*:*:*:*:*:*
- cpe:2.3:a:nokia:qt_creator:2.0.0:rc1:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- qt.nokia.com/about/news/security-announcement-qt-creator-2.0.0-for-desktop-platformsnvdPatchVendor Advisory
- www.qt.gitorious.org/qt-creator/qt-creator/commit/3c00715c8e90c57953ec4a8716110f6954e524e4nvdPatch
- www.vupen.com/english/advisories/2010/2559nvdVendor Advisory
- www.vupen.com/english/advisories/2010/2560nvdVendor Advisory
- www.mandriva.com/security/advisoriesnvd
- www.securityfocus.com/bid/43672nvd
News mentions
0No linked articles in our index yet.