Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 341567 (CVE-2010-3349) - <media-sound/ardour-2.8.11-r1: Insecure Library Loading Arbitrary Code Execution Vulnerability (CVE-2010-3349)
Summary: <media-sound/ardour-2.8.11-r1: Insecure Library Loading Arbitrary Code Execut...
Status: RESOLVED FIXED
Alias: CVE-2010-3349
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://www.securityfocus.com/bid/4410...
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2010-10-18 02:42 UTC by Tim Sammut (RETIRED)
Modified: 2011-04-30 22:33 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tim Sammut (RETIRED) gentoo-dev 2010-10-18 02:42:09 UTC
From $URL:

Ardour is prone to a vulnerability that lets attackers execute arbitrary code.

A successful exploit can allow the attacker to execute arbitrary code in the context of the user running the affected application.

Ardour 2.8.11 is vulnerable; other versions may also be affected. 


The Debian bug is significantly more useful:

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=598283
Comment 1 Tim Harder gentoo-dev 2011-04-30 19:54:34 UTC
Fixed in 2.8.11-r1 in CVS.
Comment 2 Tim Sammut (RETIRED) gentoo-dev 2011-04-30 22:33:33 UTC
(In reply to comment #1)
> Fixed in 2.8.11-r1 in CVS.

Great, thank you. Closing noglsa as this is stable on zero arches.