PT-2010-5675 · Gnu+1 · Glibc+1

Tavis Ormandy

·

Published

1970-01-01

·

Updated

2023-07-20

·

CVE-2010-3856

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions glibc versions prior to 2.11.3 glibc versions 2.12.x prior to 2.12.2
Description The issue is related to the improper restriction of the use of the LD AUDIT environment variable to reference dynamic shared objects (DSOs) as audit objects. This allows local users to gain privileges by leveraging an unsafe DSO located in a trusted library directory. The exploitation of this issue can lead to a violation of confidentiality, integrity, and availability of protected information. Exploitation can be performed locally or remotely.
Recommendations For glibc versions prior to 2.11.3, update to version 2.11.3 or later. For glibc versions 2.12.x prior to 2.12.2, update to version 2.12.2 or later. As a temporary workaround, consider restricting the use of the LD AUDIT environment variable to prevent referencing dynamic shared objects as audit objects.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2015-04440
BDU:2015-04441
BDU:2015-04442
BDU:2015-04443
BDU:2015-04444
BDU:2015-04445
BDU:2015-04446
BDU:2015-04447
BDU:2015-09412
CVE-2010-3856
DSA-2122-1
DSA-2122-2
RHSA-2010:0793
RHSA-2010:0872
RHSA-2010_0793
RHSA-2010_0872

Affected Products

Red Hat
Glibc