Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-1095

Опубликовано: 11 авг. 2010
Источник: redhat
CVSS2: 3.7
EPSS Низкий

Описание

locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not quote its output, which might allow local users to gain privileges via a crafted localization environment variable, in conjunction with a program that executes a script that uses the eval function.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=625893glibc: insufficient quoting in the locale command output

EPSS

Процентиль: 25%
0.00087
Низкий

3.7 Low

CVSS2

Связанные уязвимости

ubuntu
почти 15 лет назад

locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not quote its output, which might allow local users to gain privileges via a crafted localization environment variable, in conjunction with a program that executes a script that uses the eval function.

nvd
почти 15 лет назад

locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not quote its output, which might allow local users to gain privileges via a crafted localization environment variable, in conjunction with a program that executes a script that uses the eval function.

debian
почти 15 лет назад

locale/programs/locale.c in locale in the GNU C Library (aka glibc or ...

github
почти 4 года назад

locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not quote its output, which might allow local users to gain privileges via a crafted localization environment variable, in conjunction with a program that executes a script that uses the eval function.

oracle-oval
около 15 лет назад

ELSA-2011-0413: glibc security update (IMPORTANT)

EPSS

Процентиль: 25%
0.00087
Низкий

3.7 Low

CVSS2