MDVSA-2008:064 -- Mandriva tomboyID: oval:org.secpod.oval:def:301386 | Date: (C)2012-01-07 (M)2021-07-09 |
Class: PATCH | Family: unix |
A flaw in how tomboy handles LD_LIBRARY_PATH was discovered where by appending paths to LD_LIBRARY_PATH the program would also search the current directory for shared libraries. In directories containing network data, those libraries could be injected into the application. The updated packages have been patched to correct this issue.
Platform: |
Mandriva Linux 2007.1 |
Mandriva Linux 2008.0 |