Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p4p6-gwhq-q5q7

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 3.3

Описание

On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.

On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.

EPSS

Процентиль: 3%
0.00016
Низкий

3.3 Low

CVSS3

Дефекты

CWE-200
CWE-665

Связанные уязвимости

CVSS3: 3.3
ubuntu
около 6 лет назад

On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.

CVSS3: 2.9
redhat
около 6 лет назад

On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.

CVSS3: 3.3
nvd
около 6 лет назад

On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.

CVSS3: 3.3
msrc
больше 5 лет назад

Описание отсутствует

CVSS3: 3.3
debian
около 6 лет назад

On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 ...

EPSS

Процентиль: 3%
0.00016
Низкий

3.3 Low

CVSS3

Дефекты

CWE-200
CWE-665