{"id":"UBUNTU-CVE-2010-4001","details":"** DISPUTED ** GMXRC.bash in Gromacs 4.5.1 and earlier places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.  NOTE: CVE disputes this issue because the GMXLDLIB value is always added to the beginning of LD_LIBRARY_PATH at a later point in the script.","modified":"2010-11-06T00:00:00Z","published":"2010-11-06T00:00:00Z","withdrawn":"2025-06-23T15:52:31Z","references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2010-4001"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2010-4001"}],"affected":[{"package":{"name":"gromacs","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/gromacs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.0.6-1","5.1-1","5.1.1-1","5.1.1-2","5.1.1-2build1","5.1.2-1ubuntu1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2010/UBUNTU-CVE-2010-4001.json"}},{"package":{"name":"gromacs","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/gromacs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2016.4-1","2018-2","2018.1-1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2010/UBUNTU-CVE-2010-4001.json"}},{"package":{"name":"gromacs","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/gromacs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2019.3-2","2019.4-1","2019.4-1build1","2020-2","2020-2build1","2020.1-1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2010/UBUNTU-CVE-2010-4001.json"}},{"package":{"name":"gromacs","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/gromacs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2020.6-2","2021.4-2"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2010/UBUNTU-CVE-2010-4001.json"}},{"package":{"name":"gromacs","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/gromacs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2023.1-2ubuntu1","2023.3-1ubuntu1","2023.3-1ubuntu2","2023.3-1ubuntu3"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2010/UBUNTU-CVE-2010-4001.json"}}],"schema_version":"1.7.3"}