Multiple untrusted search path vulnerabilities in elf/dl-object.c in certain modified versions of the GNU C Library (aka glibc or libc6), including glibc-2.5-49.el5_5.6 and glibc-2.12-1.7.el6_0.3 in Red Hat Enterprise Linux, allow local users to gain privileges via a crafted dynamic shared object (DSO) in a subdirectory of the current working directory during execution of a (1) setuid or (2) setgid program that has $ORIGIN in (a) RPATH or (b) RUNPATH within the program itself or a referenced library. NOTE: this issue exists because of an incorrect fix for CVE-2010-3847.
CVSS Details
- CVSS 3.1 Base Score: 8.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade glibc-headersUpgrade glibc-develUpgrade glibc-utilsUpgrade glibc-commonUpgrade glibcUpgrade nscd | Dec 1, 2016 | Apr 8, 2011 |
| Gentoo Linux | — | Upgrade sys-libs/glibc. | Oct 30, 2017 | Apr 8, 2011 |
| Oracle_linux | — | Upgrade glibcUpgrade glibc-utilsUpgrade nscdUpgrade glibc-commonUpgrade glibc-develUpgrade glibc-headers | Oct 16, 2024 | Apr 8, 2011 |
| Suse | — | Upgrade glibc-dceext-32bitUpgrade sap-aio-releaseUpgrade glibc-develUpgrade glibc-i18ndataUpgrade glibc-htmlUpgrade glibc-devel-32bitUpgrade glibc-x86Upgrade glibc-locale-64bitUpgrade glibc-localeUpgrade glibc-profile-64bitUpgrade glibc-locale-x86Upgrade glibcUpgrade glibc-dceextUpgrade glibc-profileUpgrade glibc-dceext-x86Upgrade glibc-dceext-64bitUpgrade glibc-profile-x86Upgrade glibc-32bitUpgrade timezoneUpgrade nscdUpgrade glibc-infoUpgrade glibc-locale-32bitUpgrade glibc-profile-32bitUpgrade glibc-devel-64bitUpgrade glibc-64bit | Dec 12, 2013 | Apr 8, 2011 |
| Ubuntu | — | Upgrade eglibcUpgrade glibc | Nov 19, 2024 | Apr 8, 2011 |
| Vmsa 2011 0010 | — | Upgrade VMware ESX 4.1 to build number 433742Upgrade VMware ESX 4.0 to build number 480973 | Aug 2, 2011 | Jul 28, 2011 |
| Vmsa 2011 0012 | — | Upgrade VMware ESX 4.0 to build number 480973Upgrade VMware ESX 4.1 to build number 502767Upgrade VMware ESXi 4.0 to build number 480973Upgrade VMware ESXi 4.1 to build number 502767Upgrade VMware ESXi 5.0 to build number 515841 | Oct 20, 2011 | Apr 8, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub