Upstream information

CVE-2010-4001 at MITRE

Description

** DISPUTED ** GMXRC.bash in Gromacs 4.5.1 and earlier places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: CVE disputes this issue because the GMXLDLIB value is always added to the beginning of LD_LIBRARY_PATH at a later point in the script.

SUSE information

Overall state of this security issue: Ignore

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 4.6
Vector AV:L/AC:L/Au:N/C:P/I:P/A:P
Access Vector Local
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
SUSE Bugzilla entry: 642828 [RESOLVED / FIXED]

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
openSUSE Tumbleweed
  • gromacs >= 2016.1-1.1
  • gromacs-bash >= 2016.1-1.1
  • gromacs-devel >= 2016.1-1.1
  • gromacs-doc >= 2016.1-1.1
  • gromacs-openmpi >= 2016.1-1.1
  • libgromacs2 >= 2016.1-1.1
Patchnames:
openSUSE Tumbleweed GA gromacs