PT-2001-1048 · Gnu · Glibc

Published

2001-03-26

·

Updated

2017-10-10

·

CVE-2001-0169

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions glibc versions 2.1.3
Description The issue affects the glibc package in Red Hat Linux, potentially leading to breaches of confidentiality, integrity, and availability of protected information. Exploitation can be carried out remotely. A specific concern is the use of the LD PRELOAD environmental variable in SUID or SGID applications, where glibc fails to verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID. This could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.
Recommendations For glibc version 2.1.3, consider restricting the use of the LD PRELOAD environmental variable in SUID or SGID applications until a patch is available. As a temporary workaround, ensure that all preloaded libraries in /etc/ld.so.cache are properly set as SUID/SGID to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-07993
BDU:2015-08004
BDU:2015-08008
CVE-2001-0169

Affected Products

Glibc