Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-3847

Опубликовано: 07 янв. 2011
Источник: ubuntu
Приоритет: negligible
EPSS Низкий
CVSS2: 6.9

Описание

elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via a crafted dynamic shared object (DSO) located in an arbitrary directory.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

hardy

DNE

jaunty

DNE

karmic

released

2.10.1-0ubuntu18
lucid

released

2.11.1-0ubuntu7.5
maverick

released

2.12.1-0ubuntu8
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

not-affected

devel

DNE

hardy

released

2.7-10ubuntu7
jaunty

released

2.9-4ubuntu6.3
karmic

DNE

lucid

DNE

maverick

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 89%
0.04983
Низкий

6.9 Medium

CVSS2

Связанные уязвимости

redhat
больше 14 лет назад

elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via a crafted dynamic shared object (DSO) located in an arbitrary directory.

nvd
больше 14 лет назад

elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via a crafted dynamic shared object (DSO) located in an arbitrary directory.

debian
больше 14 лет назад

elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) throu ...

github
около 3 лет назад

elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via a crafted dynamic shared object (DSO) located in an arbitrary directory.

oracle-oval
больше 14 лет назад

ELSA-2010-0787: glibc security update (IMPORTANT)

EPSS

Процентиль: 89%
0.04983
Низкий

6.9 Medium

CVSS2