Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-19126

Опубликовано: 19 нояб. 2019
Источник: nvd
CVSS3: 3.3
CVSS2: 2.1
EPSS Низкий

Описание

On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:x64:*
Версия до 2.31 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
Конфигурация 4
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 6%
0.00024
Низкий

3.3 Low

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-665

Связанные уязвимости

CVSS3: 3.3
ubuntu
около 6 лет назад

On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.

CVSS3: 2.9
redhat
около 6 лет назад

On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.

CVSS3: 3.3
msrc
больше 5 лет назад

Описание отсутствует

CVSS3: 3.3
debian
около 6 лет назад

On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 ...

suse-cvrf
около 6 лет назад

Security update for glibc

EPSS

Процентиль: 6%
0.00024
Низкий

3.3 Low

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-665