|
|
| |
|
| |
glibc: privilege escalation
| Package(s): | glibc |
CVE #(s): | CVE-2010-3847
|
| Created: | October 21, 2010 |
Updated: | April 15, 2011 |
| Description: |
From the Red Hat advisory:
It was discovered that the glibc dynamic linker/loader did not handle the
$ORIGIN dynamic string token set in the LD_AUDIT environment variable
securely. A local attacker with write access to a file system containing
setuid or setgid binaries could use this flaw to escalate their privileges.
(CVE-2010-3847)
For a detailed look, see Tavis Ormandy's report.
|
| Alerts: |
|
( Log in to post comments)
|
|
|