CVE-2010-3350 describes a local privilege escalation vulnerability in bareFTP version 0.3.4. The application incorrectly adds a zero-length directory to the LD_LIBRARY_PATH, allowing an attacker to execute malicious code via a Trojan horse shared library placed in the current working directory. With a CVSS score of 6.9 (high severity), this flaw permits an attacker to achieve full compromise of confidentiality, integrity, and availability on the affected system, though it requires local access and medium attack complexity. There is no evidence of active exploitation, nor are there public exploits available in Metasploit or ExploitDB, but the vulnerability has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.3.4CPE matchmatch criteria | cpe:2.3:a:bareftp:bareftp:0.3.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.