Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2011-1095

Опубликовано: 10 апр. 2011
Источник: debian
EPSS Низкий

Описание

locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not quote its output, which might allow local users to gain privileges via a crafted localization environment variable, in conjunction with a program that executes a script that uses the eval function.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
glibcfixed2.13-16package
glibcno-dsalennypackage
eglibcfixed2.13-16package
eglibcfixed2.11.3-2squeezepackage

Примечания

  • http://sources.redhat.com/bugzilla/show_bug.cgi?id=11904

  • http://bugs.gentoo.org/show_bug.cgi?id=330923

EPSS

Процентиль: 24%
0.00078
Низкий

Связанные уязвимости

ubuntu
около 14 лет назад

locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not quote its output, which might allow local users to gain privileges via a crafted localization environment variable, in conjunction with a program that executes a script that uses the eval function.

redhat
почти 15 лет назад

locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not quote its output, which might allow local users to gain privileges via a crafted localization environment variable, in conjunction with a program that executes a script that uses the eval function.

nvd
около 14 лет назад

locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not quote its output, which might allow local users to gain privileges via a crafted localization environment variable, in conjunction with a program that executes a script that uses the eval function.

github
около 3 лет назад

locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not quote its output, which might allow local users to gain privileges via a crafted localization environment variable, in conjunction with a program that executes a script that uses the eval function.

oracle-oval
около 14 лет назад

ELSA-2011-0413: glibc security update (IMPORTANT)

EPSS

Процентиль: 24%
0.00078
Низкий