magics-config in Magics++ 2.10.0 places a zero-length directory name in the LDLIBRARYPATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libmagics++-data",
"binary_version": "2.18.15-5"
},
{
"binary_name": "libmagics++-dev",
"binary_version": "2.18.15-5"
},
{
"binary_name": "libmagics++-metview-dev",
"binary_version": "2.18.15-5"
},
{
"binary_name": "libmagplus3",
"binary_version": "2.18.15-5"
},
{
"binary_name": "magics++",
"binary_version": "2.18.15-5"
},
{
"binary_name": "python-magics++",
"binary_version": "2.18.15-5"
}
]
}