Unrated severityNVD Advisory· Published Nov 6, 2010· Updated Apr 29, 2026
CVE-2010-3998
CVE-2010-3998
Description
The (1) banshee-1 and (2) muinshee scripts in Banshee 1.8.0 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: Banshee might also be affected using GST_PLUGIN_PATH.
Affected products
24cpe:2.3:a:banshee-project:banshee:*:*:*:*:*:*:*:*+ 23 more
- cpe:2.3:a:banshee-project:banshee:*:*:*:*:*:*:*:*range: <=1.8.0
- cpe:2.3:a:banshee-project:banshee:0.13.2:*:*:*:*:*:*:*
- cpe:2.3:a:banshee-project:banshee:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:banshee-project:banshee:1.2:*:*:*:*:*:*:*
- cpe:2.3:a:banshee-project:banshee:1.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:banshee-project:banshee:1.4:*:*:*:*:*:*:*
- cpe:2.3:a:banshee-project:banshee:1.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:banshee-project:banshee:1.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:banshee-project:banshee:1.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:banshee-project:banshee:1.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:banshee-project:banshee:1.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:banshee-project:banshee:1.5.3:*:*:*:*:*:*:*
- cpe:2.3:a:banshee-project:banshee:1.5.4:*:*:*:*:*:*:*
- cpe:2.3:a:banshee-project:banshee:1.5.5:*:*:*:*:*:*:*
- cpe:2.3:a:banshee-project:banshee:1.5.6:*:*:*:*:*:*:*
- cpe:2.3:a:banshee-project:banshee:1.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:banshee-project:banshee:1.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:banshee-project:banshee:1.7.0:*:*:*:*:*:*:*
- cpe:2.3:a:banshee-project:banshee:1.7.1:*:*:*:*:*:*:*
- cpe:2.3:a:banshee-project:banshee:1.7.2:*:*:*:*:*:*:*
- cpe:2.3:a:banshee-project:banshee:1.7.3:*:*:*:*:*:*:*
- cpe:2.3:a:banshee-project:banshee:1.7.4:*:*:*:*:*:*:*
- cpe:2.3:a:banshee-project:banshee:1.7.5:*:*:*:*:*:*:*
- cpe:2.3:a:banshee-project:banshee:1.7.6:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- bugzilla.redhat.com/show_bug.cginvdExploit
- download.banshee.fm/banshee/unstable/1.9.0/banshee-1-1.9.0.newsnvd
- lists.fedoraproject.org/pipermail/package-announce/2010-November/050744.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2010-November/050747.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2010-November/050756.htmlnvd
- secunia.com/advisories/42234nvd
- secunia.com/advisories/42237nvd
- www.mandriva.com/security/advisoriesnvd
- www.securityfocus.com/bid/44752nvd
- www.vupen.com/english/advisories/2010/2964nvd
News mentions
0No linked articles in our index yet.