Red Hat Bugzilla – Bug 447705
CVE-2008-1951 sblim: libraries built with insecure RPATH
Last modified: 2012-04-10 13:53:10 EDT
It was discovered that libraries shipped in sblim packages in Red Hat Enterprise
Linux 4 and 5 have RPATH set pointing to a directory in a world-writable
/var/tmp/sblim-<version>-<release>-root-brewbuilder//usr/lib . That directory
existed on the build system during the package build, but is unlikely to exist
on systems where sblim packages are installed.
This issue can be exploited by a local user to create fake library required by
sblim libraries and execute arbitrary code with the privileges of the
application using sblim such as tog-pegasus.
This issue was addressed in:
Red Hat Enterprise Linux: