Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-10219

Опубликовано: 25 авг. 2025
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2025-10219: glibc security update (MODERATE)

[2.17-326.0.11.3]

  • Back port fix for CVE-2025-4802 [Orabug: 38144086]

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

glibc

2.17-326.0.11.el7_9.3

glibc-common

2.17-326.0.11.el7_9.3

glibc-devel

2.17-326.0.11.el7_9.3

glibc-headers

2.17-326.0.11.el7_9.3

glibc-static

2.17-326.0.11.el7_9.3

glibc-utils

2.17-326.0.11.el7_9.3

nscd

2.17-326.0.11.el7_9.3

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
6 месяцев назад

Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).

CVSS3: 7
redhat
6 месяцев назад

Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).

CVSS3: 7.8
nvd
6 месяцев назад

Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).

CVSS3: 8.4
msrc
2 месяца назад

Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).

CVSS3: 7.8
debian
6 месяцев назад

Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GN ...