elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via a crafted dynamic shared object (DSO) located in an arbitrary directory.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade glibc-utilsUpgrade glibc-commonUpgrade glibc-headersUpgrade glibc-develUpgrade glibcUpgrade nscd | Dec 1, 2016 | Jan 7, 2011 |
| Debian | — | Upgrade glibc | Jul 30, 2024 | Jan 7, 2011 |
| Gentoo Linux | — | Upgrade sys-libs/glibc. | Oct 30, 2017 | Jan 7, 2011 |
| Oracle_linux | — | Upgrade glibc-staticUpgrade glibc-headersUpgrade nscdUpgrade glibc-develUpgrade glibc-commonUpgrade glibcUpgrade glibc-utils | Oct 16, 2024 | Jan 7, 2011 |
| Suse | — | Upgrade glibc-i18ndataUpgrade glibcUpgrade glibc-develUpgrade glibc-profileUpgrade glibc-x86Upgrade nscdUpgrade glibc-localeUpgrade glibc-profile-x86Upgrade glibc-locale-32bitUpgrade glibc-infoUpgrade glibc-32bitUpgrade glibc-locale-x86Upgrade glibc-profile-32bitUpgrade glibc-htmlUpgrade glibc-devel-32bit | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libc6 | Nov 8, 2024 | Jan 7, 2011 |
| Vmsa 2011 0001 | — | Upgrade VMware ESX 4.0 to build number 332073Upgrade VMware ESX 4.1 to build number 348481 | Jan 5, 2011 | Jan 5, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub