A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.
CVSS Details
- CVSS 3.0 Base Score: 7
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade glibc | Jul 30, 2024 | Feb 1, 2018 |
| Suse | — | Upgrade glibc-i18ndataUpgrade glibc-htmlUpgrade glibc-utilsUpgrade glibc-langUpgrade glibc-locale-baseUpgrade glibc-develUpgrade glibc-locale-32bitUpgrade glibc-localeUpgrade glibcUpgrade glibc-devel-32bitUpgrade glibc-devel-staticUpgrade glibc-infoUpgrade glibc-profileUpgrade nscdUpgrade glibc-32bitUpgrade glibc-extraUpgrade glibc-profile-32bitUpgrade glibc-locale-base-32bit | Jan 13, 2018 | Jan 12, 2018 |
| Ubuntu | — | Upgrade libc6 | Jan 18, 2018 | Jan 12, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub