CVE
- Id
- 34982
- CVE No.
- CVE-2008-4865
- Status
- Candidate
- Description
- Untrusted search path vulnerability in valgrind before 3.4.0 allows local users to execute arbitrary programs via a Trojan horse .valgrindrc file in the current working directory, as demonstrated using a malicious --db-command options. NOTE: the severity of this issue has been disputed, but CVE is including this issue because execution of a program from an untrusted directory is a common scenario.
- Phase
- Assigned (20081031)
- Votes
- None (candidate not yet proposed)
- Comments