Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-19126

Опубликовано: 19 нояб. 2019
Источник: ubuntu
Приоритет: low
CVSS2: 2.1
CVSS3: 3.3

Описание

On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.

РелизСтатусПримечание
bionic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-infra-legacy/trusty

not-affected

esm-infra/focal

DNE

focal

DNE

precise/esm

not-affected

trusty

ignored

end of standard support
trusty/esm

not-affected

Показывать по

РелизСтатусПримечание
bionic

released

2.27-3ubuntu1.2
devel

not-affected

2.31-0ubuntu7
disco

ignored

end of life
eoan

released

2.30-0ubuntu2.2
esm-infra-legacy/trusty

DNE

esm-infra/bionic

released

2.27-3ubuntu1.2
esm-infra/focal

not-affected

2.31-0ubuntu7
esm-infra/xenial

released

2.23-0ubuntu11.2
focal

not-affected

2.31-0ubuntu7
precise/esm

DNE

Показывать по

2.1 Low

CVSS2

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 2.9
redhat
около 6 лет назад

On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.

CVSS3: 3.3
nvd
около 6 лет назад

On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.

CVSS3: 3.3
msrc
больше 5 лет назад

Описание отсутствует

CVSS3: 3.3
debian
около 6 лет назад

On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 ...

suse-cvrf
около 6 лет назад

Security update for glibc

2.1 Low

CVSS2

3.3 Low

CVSS3