Back to Database
Status published
Medium
CVE-2010-3374
Qt Creator before 2.0.1 places a zero-length directory name in...
Vulnerability Description
Qt Creator before 2.0.1 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-3374
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.vupen.com/english/advisories/2010/2559
- http://www.qt.gitorious.org/qt-creator/qt-creator/commit/3c00715c8e90c57953ec4a8716110f6954e524e4
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:193
- http://www.securityfocus.com/bid/43672
- http://www.vupen.com/english/advisories/2010/2560
- http://qt.nokia.com/about/news/security-announcement-qt-creator-2.0.0-for-desktop-platforms
More from nokia
View All →CVE-2022-43675
An issue was discovered in NOKIA NFM-T R19.9. Reflected XSS...
Medium
6.1
CVE-2022-41763
An issue was discovered in NOKIA AMS 9.7.05. Remote Code...
High
8.8
CVE-2022-41762
An issue was discovered in NOKIA NFM-T R19.9. Multiple Reflected...
Medium
6.1
CVE-2022-41761
An issue was discovered in NOKIA NFM-T R19.9. An Absolute...
Medium
6.5
CVE-2022-41760
An issue was discovered in NOKIA NFM-T R19.9. Relative Path...
Medium
6.5
Affected Vendor
nokia
View all reports →Affected Software
qt creator
Vulnerable Versions:
0, 0.9.1, 0.9.2, 1.0.0, 1.1.0, 1.2.0, 1.2.90, 1.3.0, 1.3.1, 2.0.0
Timeline
Official Publish:
October 4th, 2010
Last Modified:
September 16th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.