Lucene search

K
osvGoogleOSV:DSA-2122-1
HistoryOct 22, 2010 - 12:00 a.m.

glibc - local privilege escalation

2010-10-2200:00:00
Google
osv.dev
21

0.001 Low

EPSS

Percentile

31.1%

Ben Hawkes and Tavis Ormandy discovered that the dynamic loader in GNU
libc allows local users to gain root privileges using a crafted
LD_AUDIT environment variable.

For the stable distribution (lenny), this problem has been fixed in
version 2.7-18lenny6.

For the upcoming stable distribution (squeeze), this problem has been
fixed in version 2.11.2-6+squeeze1 of the eglibc package.

For the unstable distribution (sid), this problem will be fixed soon.

We recommend that you upgrade your glibc packages.