monero-wallet-gui in Monero GUI before 0.17.1.0 includes the . directory in an embedded RPATH (with a preference ahead of /usr/lib), which allows local users to gain privileges via a Trojan horse library in the current working directory.
References
Link | Resource |
---|---|
https://github.com/monero-project/monero-gui/commit/6ed536982953d870010d8fa065dccbffeb6cae50 | Patch Third Party Advisory |
https://github.com/monero-project/monero-gui/issues/3142#issuecomment-705940446 | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-10-10T20:05:49
Updated: 2020-10-28T12:26:11
Reserved: 2020-10-10T00:00:00
Link: CVE-2020-26947
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-10-10T21:15:11.957
Modified: 2022-04-28T18:23:00.077
Link: CVE-2020-26947
JSON object: View
Redhat Information
No data.
CWE