CVE-2010-3387 describes a local privilege escalation vulnerability in Video Disk Recorder (VDR) version 1.6.0, specifically within the vdrleaktest script, affecting products like tvdr and vdr. The flaw arises from the script's erroneous use of a zero-length directory name in LD_LIBRARY_PATH, enabling local users to execute arbitrary code with elevated privileges via a malicious shared library. This vulnerability has a CVSS score of 6.9, indicating high severity due to its potential for complete compromise of confidentiality, integrity, and availability with medium attack complexity. While there is no known active exploitation, publicly available exploit code, or Metasploit/Nuclei modules, the CVE has garnered significant community discussion with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.6.0CPE matchmatch criteria | cpe:2.3:a:tvdr:vdr:1.6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.