ld.so in the GNU C Library (aka glibc or libc6) 2.13 and earlier expands the $ORIGIN dynamic string token when RPATH is composed entirely of this token, which might allow local users to gain privileges by creating a hard link in an arbitrary directory to a (1) setuid or (2) setgid program with this RPATH value, and then executing the program with a crafted value for the LD_PRELOAD environment variable, a different vulnerability than CVE-2010-3847 and CVE-2011-0536. NOTE: it is not expected that any standard operating-system distribution would ship an applicable setuid or setgid program.
CVSS Details
- CVSS 3.1 Base Score: 4.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade glibc-commonUpgrade glibc-develUpgrade nscdUpgrade glibcUpgrade glibc-headersUpgrade glibc-utils | Dec 1, 2016 | Apr 8, 2011 |
| Gentoo Linux | — | Upgrade sys-libs/glibc. | Oct 30, 2017 | Apr 8, 2011 |
| Oracle_linux | — | Upgrade glibc-commonUpgrade glibc-develUpgrade glibc-headersUpgrade glibcUpgrade glibc-utilsUpgrade nscd | Oct 16, 2024 | Apr 8, 2011 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 12, 2011 |
| Ubuntu | — | Upgrade libc-binUpgrade libc6 | Nov 8, 2024 | Apr 8, 2011 |
| Vmsa 2011 0010 | — | Upgrade VMware ESX 4.0 to build number 480973Upgrade VMware ESX 4.1 to build number 433742 | Dec 17, 2012 | Apr 8, 2011 |
| Vmsa 2011 0012 | — | Upgrade VMware ESXi 4.0 to build number 480973Upgrade VMware ESX 4.1 to build number 502767Upgrade VMware ESXi 5.0 to build number 515841Upgrade VMware ESX 4.0 to build number 480973Upgrade VMware ESXi 4.1 to build number 502767 | Oct 20, 2011 | Apr 8, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub