Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2000-0824

Опубликовано: 14 нояб. 2000
Источник: nvd
CVSS2: 7.2
EPSS Низкий

Описание

The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arbitrary commands in setuid programs by specifying their own duplicate environmental variables such as LD_PRELOAD or LD_LIBRARY_PATH.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gnu:glibc:2.1.1:*:*:*:*:*:*:*

EPSS

Процентиль: 53%
0.00306
Низкий

7.2 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

redhat
почти 26 лет назад

The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arbitrary commands in setuid programs by specifying their own duplicate environmental variables such as LD_PRELOAD or LD_LIBRARY_PATH.

github
около 3 лет назад

The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arbitrary commands in setuid programs by specifying their own duplicate environmental variables such as LD_PRELOAD or LD_LIBRARY_PATH.

EPSS

Процентиль: 53%
0.00306
Низкий

7.2 High

CVSS2

Дефекты

NVD-CWE-Other