Логотип exploitDog
bind:CVE-2009-4146
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2009-4146

Количество 3

Количество 3

nvd логотип

CVE-2009-4146

около 16 лет назад

The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1, 7.2, and 8.0 does not clear the LD_PRELOAD environment variable, which allows local users to gain privileges by executing a setuid or setguid program with a modified LD_PRELOAD variable containing an untrusted search path that points to a Trojan horse library, a different vector than CVE-2009-4147.

CVSS2: 7.2
EPSS: Средний
debian логотип

CVE-2009-4146

около 16 лет назад

The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld- ...

CVSS2: 7.2
EPSS: Средний
github логотип

GHSA-q9qx-32qq-p7r3

почти 4 года назад

The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1, 7.2, and 8.0 does not clear the LD_PRELOAD environment variable, which allows local users to gain privileges by executing a setuid or setguid program with a modified LD_PRELOAD variable containing an untrusted search path that points to a Trojan horse library, a different vector than CVE-2009-4147.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2009-4146

The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1, 7.2, and 8.0 does not clear the LD_PRELOAD environment variable, which allows local users to gain privileges by executing a setuid or setguid program with a modified LD_PRELOAD variable containing an untrusted search path that points to a Trojan horse library, a different vector than CVE-2009-4147.

CVSS2: 7.2
18%
Средний
около 16 лет назад
debian логотип
CVE-2009-4146

The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld- ...

CVSS2: 7.2
18%
Средний
около 16 лет назад
github логотип
GHSA-q9qx-32qq-p7r3

The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1, 7.2, and 8.0 does not clear the LD_PRELOAD environment variable, which allows local users to gain privileges by executing a setuid or setguid program with a modified LD_PRELOAD variable containing an untrusted search path that points to a Trojan horse library, a different vector than CVE-2009-4147.

18%
Средний
почти 4 года назад

Уязвимостей на страницу