Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q3fw-v7x4-w8hh

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via a crafted dynamic shared object (DSO) located in an arbitrary directory.

elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via a crafted dynamic shared object (DSO) located in an arbitrary directory.

EPSS

Процентиль: 89%
0.04983
Низкий

Дефекты

CWE-59

Связанные уязвимости

ubuntu
больше 14 лет назад

elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via a crafted dynamic shared object (DSO) located in an arbitrary directory.

redhat
больше 14 лет назад

elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via a crafted dynamic shared object (DSO) located in an arbitrary directory.

nvd
больше 14 лет назад

elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via a crafted dynamic shared object (DSO) located in an arbitrary directory.

debian
больше 14 лет назад

elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) throu ...

oracle-oval
больше 14 лет назад

ELSA-2010-0787: glibc security update (IMPORTANT)

EPSS

Процентиль: 89%
0.04983
Низкий

Дефекты

CWE-59