PT-2001-1016 · Red Hat+1 · Red Hat+1

Published

2001-01-11

·

Updated

2017-10-10

·

CVE-2001-0170

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions glibc versions 2.1.9x and earlier glibc-2.2 glibc-common-2.2 glibc-devel-2.2 glibc-profile-2.2
Description The issue affects the glibc package in Red Hat Linux, potentially leading to a breach of protected information confidentiality. Exploitation can be carried out locally. The vulnerability is related to the improper clearing of environmental variables such as RESOLV HOST CONF, HOSTALIASES, or RES OPTIONS when executing setuid/setgid programs, which could allow local users to read arbitrary files.
Recommendations For glibc versions 2.1.9x and earlier, update to a version later than 2.1.9x to resolve the issue. For glibc-2.2, glibc-common-2.2, glibc-devel-2.2, and glibc-profile-2.2, consider disabling setuid/setgid programs that utilize the vulnerable glibc package until a patch is available. As a temporary workaround, restrict access to sensitive files and directories to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-07776
BDU:2015-07777
BDU:2015-07778
BDU:2015-07779
CVE-2001-0170

Affected Products

Red Hat
Glibc