ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment variable to reference dynamic shared objects (DSOs) as audit objects, which allows local users to gain privileges by leveraging an unsafe DSO located in a trusted library directory, as demonstrated by libpcprofile.so.
CVSS Details
- CVSS 3.1 Base Score: 8.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade glibc-commonUpgrade nscdUpgrade glibc-utilsUpgrade glibc-develUpgrade glibcUpgrade glibc-headers | Dec 1, 2016 | Jan 7, 2011 |
| Debian | — | Upgrade glibc | Jul 30, 2024 | Jan 7, 2011 |
| Gentoo Linux | — | Upgrade sys-libs/glibc. | Oct 30, 2017 | Jan 7, 2011 |
| Oracle_linux | — | Upgrade glibc-commonUpgrade glibc-headersUpgrade glibcUpgrade nscdUpgrade glibc-develUpgrade glibc-utils | Oct 16, 2024 | Jan 7, 2011 |
| Suse | — | Upgrade glibc-i18ndataUpgrade glibc-dceext-32bitUpgrade glibc-develUpgrade glibc-64bitUpgrade glibc-profile-x86Upgrade glibc-locale-32bitUpgrade glibc-x86Upgrade glibc-localeUpgrade glibcUpgrade glibc-locale-x86Upgrade glibc-profileUpgrade sap-aio-releaseUpgrade glibc-dceext-x86Upgrade glibc-devel-64bitUpgrade glibc-obsoleteUpgrade glibc-devel-32bitUpgrade glibc-32bitUpgrade glibc-profile-32bitUpgrade glibc-locale-64bitUpgrade nscdUpgrade glibc-infoUpgrade glibc-dceext-64bitUpgrade glibc-dceextUpgrade glibc-htmlUpgrade glibc-profile-64bit | Dec 12, 2013 | Jan 7, 2011 |
| Ubuntu | — | Upgrade libc6 | Nov 8, 2024 | Jan 7, 2011 |
| Vmsa 2011 0001 | — | Upgrade VMware ESX 4.0 to build number 332073Upgrade VMware ESX 4.1 to build number 348481 | Jan 5, 2011 | Jan 5, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub