CVE-2001-0169
Published Mar 26, 2001
Last updated 7 years ago
Overview
- Description
- When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 2.1
- Impact score
- 2.9
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:mandrakesoft:mandrake_linux:6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D323A6B7-2741-4F31-B0D6-5D6FB738A2A1" }, { "criteria": "cpe:2.3:o:mandrakesoft:mandrake_linux:6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ACAAD334-2CA7-4B3B-BA25-302E7610BC2A" }, { "criteria": "cpe:2.3:o:mandrakesoft:mandrake_linux:7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E4853E92-5E0A-47B9-A343-D5BEE87D2C27" }, { "criteria": "cpe:2.3:o:mandrakesoft:mandrake_linux:7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3EC1FF5D-5EAB-44D5-B281-770547C70D68" }, { "criteria": "cpe:2.3:o:mandrakesoft:mandrake_linux:7.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0A8FBD5A-2FD0-43CD-AC4B-1D6984D336FE" }, { "criteria": "cpe:2.3:o:mandrakesoft:mandrake_linux_corporate_server:1.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "97E09AD9-F057-4264-88BB-A8A18C1B1246" }, { "criteria": "cpe:2.3:o:redhat:linux:6.0:*:alpha:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6931FB54-A163-4CE3-BBD9-D345AA0977A6" }, { "criteria": "cpe:2.3:o:redhat:linux:6.0:*:i386:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "89F65C9D-BD68-4A86-BFDC-E7CE76F13948" }, { "criteria": "cpe:2.3:o:redhat:linux:6.0:*:sparc:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5ABD1331-277C-4C31-8186-978243C62255" }, { "criteria": "cpe:2.3:o:redhat:linux:6.1:*:alpha:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C89454B9-4F45-4A42-A06D-ED42D893C544" }, { "criteria": "cpe:2.3:o:redhat:linux:6.1:*:i386:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B72D6205-DFA4-41D9-B3B6-0B7DA756CD8F" }, { "criteria": "cpe:2.3:o:redhat:linux:6.1:*:sparc:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1E64093E-7D53-4238-95C3-48ED5A0FFD97" }, { "criteria": "cpe:2.3:o:redhat:linux:6.2:*:alpha:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "344610A8-DB6D-4407-9304-916C419F648C" }, { "criteria": "cpe:2.3:o:redhat:linux:6.2:*:i386:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B7EC2B95-4715-4EC9-A10A-2542501F8A61" }, { "criteria": "cpe:2.3:o:redhat:linux:6.2:*:sparc:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "64775BEF-2E53-43CA-8639-A7E54F6F4222" }, { "criteria": "cpe:2.3:o:trustix:secure_linux:1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9D0DFB12-B43F-4207-A900-464A97F5124D" }, { "criteria": "cpe:2.3:o:trustix:secure_linux:1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "13EBB2F7-712E-4CB1-B4B4-5F0851F3D37E" }, { "criteria": "cpe:2.3:o:turbolinux:turbolinux:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A94B142D-DA33-41BF-9398-C7ABB94C30DF", "versionEndIncluding": "6.0.5" }, { "criteria": "cpe:2.3:o:turbolinux:turbolinux:6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CCEBB085-ECEE-4E18-951B-FC15C0646047" } ], "operator": "OR" } ] } ]