UBUNTU-CVE-2010-4337

Source
https://ubuntu.com/security/CVE-2010-4337
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2010/UBUNTU-CVE-2010-4337.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2010-4337
Upstream
  • CVE-2010-4337
Withdrawn
2025-07-18T16:42:40Z
Published
2011-01-14T23:00:00Z
Modified
2025-07-16T08:10:27.038138Z
Severity
  • Ubuntu - low
Summary
[none]
Details

The configure script in gnash 0.8.8 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/gnash-configure-errors.$$, (2) /tmp/gnash-configure-warnings.$$, or (3) /tmp/gnash-configure-recommended.$$ files.

References

Affected packages

Ubuntu:14.04:LTS / gnash

Package

Name
gnash
Purl
pkg:deb/ubuntu/gnash@0.8.11~git20130903-3ubuntu1?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.8.11~git20130903-3ubuntu1

Affected versions

0.*
0.8.11~git20120629-1ubuntu3
0.8.11~git20120629-1ubuntu4

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "browser-plugin-gnash",
            "binary_version": "0.8.11~git20130903-3ubuntu1"
        },
        {
            "binary_name": "gnash",
            "binary_version": "0.8.11~git20130903-3ubuntu1"
        },
        {
            "binary_name": "gnash-common",
            "binary_version": "0.8.11~git20130903-3ubuntu1"
        },
        {
            "binary_name": "gnash-common-opengl",
            "binary_version": "0.8.11~git20130903-3ubuntu1"
        },
        {
            "binary_name": "gnash-cygnal",
            "binary_version": "0.8.11~git20130903-3ubuntu1"
        },
        {
            "binary_name": "gnash-dbg",
            "binary_version": "0.8.11~git20130903-3ubuntu1"
        },
        {
            "binary_name": "gnash-dev",
            "binary_version": "0.8.11~git20130903-3ubuntu1"
        },
        {
            "binary_name": "gnash-doc",
            "binary_version": "0.8.11~git20130903-3ubuntu1"
        },
        {
            "binary_name": "gnash-ext-fileio",
            "binary_version": "0.8.11~git20130903-3ubuntu1"
        },
        {
            "binary_name": "gnash-ext-lirc",
            "binary_version": "0.8.11~git20130903-3ubuntu1"
        },
        {
            "binary_name": "gnash-ext-mysql",
            "binary_version": "0.8.11~git20130903-3ubuntu1"
        },
        {
            "binary_name": "gnash-opengl",
            "binary_version": "0.8.11~git20130903-3ubuntu1"
        },
        {
            "binary_name": "gnash-tools",
            "binary_version": "0.8.11~git20130903-3ubuntu1"
        },
        {
            "binary_name": "klash",
            "binary_version": "0.8.11~git20130903-3ubuntu1"
        },
        {
            "binary_name": "klash-opengl",
            "binary_version": "0.8.11~git20130903-3ubuntu1"
        },
        {
            "binary_name": "konqueror-plugin-gnash",
            "binary_version": "0.8.11~git20130903-3ubuntu1"
        },
        {
            "binary_name": "mozilla-plugin-gnash",
            "binary_version": "0.8.11~git20130903-3ubuntu1"
        },
        {
            "binary_name": "python-gtk-gnash",
            "binary_version": "0.8.11~git20130903-3ubuntu1"
        },
        {
            "binary_name": "swfdec-gnome",
            "binary_version": "1:0.8.11~git20130903-3ubuntu1"
        },
        {
            "binary_name": "swfdec-mozilla",
            "binary_version": "0.8.11~git20130903-3ubuntu1"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2010/UBUNTU-CVE-2010-4337.json"

Ubuntu:16.04:LTS / gnash

Package

Name
gnash
Purl
pkg:deb/ubuntu/gnash@0.8.11~git20160109-1build1?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.8.11~git20160109-1build1

Affected versions

0.*
0.8.11~git20150419-3build1
0.8.11~git20150419-3build2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "browser-plugin-gnash",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "browser-plugin-gnash-dbgsym",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "gnash",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "gnash-common",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "gnash-common-dbgsym",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "gnash-common-opengl",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "gnash-cygnal",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "gnash-cygnal-dbgsym",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "gnash-dbg",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "gnash-dbgsym",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "gnash-dev",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "gnash-dev-dbgsym",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "gnash-doc",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "gnash-ext-fileio",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "gnash-ext-fileio-dbgsym",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "gnash-ext-lirc",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "gnash-ext-lirc-dbgsym",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "gnash-ext-mysql",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "gnash-ext-mysql-dbgsym",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "gnash-opengl",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "gnash-tools",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "gnash-tools-dbgsym",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "klash",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "klash-dbgsym",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "klash-opengl",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "konqueror-plugin-gnash",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "konqueror-plugin-gnash-dbgsym",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "mozilla-plugin-gnash",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "python-gtk-gnash",
            "binary_version": "0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "swfdec-gnome",
            "binary_version": "1:0.8.11~git20160109-1build1"
        },
        {
            "binary_name": "swfdec-mozilla",
            "binary_version": "0.8.11~git20160109-1build1"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2010/UBUNTU-CVE-2010-4337.json"