PT-2001-1016 · Red Hat+1 · Red Hat+1

Publicado

2001-01-11

·

Atualizado

2017-10-10

·

CVE-2001-0170

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions glibc versions 2.1.9x and earlier glibc-2.2 glibc-common-2.2 glibc-devel-2.2 glibc-profile-2.2
Description The issue affects the glibc package in Red Hat Linux, potentially leading to a breach of protected information confidentiality. Exploitation can be carried out locally. The vulnerability is related to the improper clearing of environmental variables such as RESOLV HOST CONF, HOSTALIASES, or RES OPTIONS when executing setuid/setgid programs, which could allow local users to read arbitrary files.
Recommendations For glibc versions 2.1.9x and earlier, update to a version later than 2.1.9x to resolve the issue. For glibc-2.2, glibc-common-2.2, glibc-devel-2.2, and glibc-profile-2.2, consider disabling setuid/setgid programs that utilize the vulnerable glibc package until a patch is available. As a temporary workaround, restrict access to sensitive files and directories to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-07776
BDU:2015-07777
BDU:2015-07778
BDU:2015-07779
CVE-2001-0170

Produtos afetados

Red Hat
Glibc