PT-2001-1048 · Gnu · Glibc

Publicado

2001-03-26

·

Atualizado

2017-10-10

·

CVE-2001-0169

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions glibc versions 2.1.3
Description The issue affects the glibc package in Red Hat Linux, potentially leading to breaches of confidentiality, integrity, and availability of protected information. Exploitation can be carried out remotely. A specific concern is the use of the LD PRELOAD environmental variable in SUID or SGID applications, where glibc fails to verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID. This could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.
Recommendations For glibc version 2.1.3, consider restricting the use of the LD PRELOAD environmental variable in SUID or SGID applications until a patch is available. As a temporary workaround, ensure that all preloaded libraries in /etc/ld.so.cache are properly set as SUID/SGID to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-07993
BDU:2015-08004
BDU:2015-08008
CVE-2001-0169

Produtos afetados

Glibc