Lucene search

K
prionPRIOn knowledge basePRION:CVE-2009-4147
HistoryDec 02, 2009 - 7:30 p.m.

Code injection

2009-12-0219:30:00
PRIOn knowledge base
www.prio-n.com
3

6.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1 and 8.0 does not clear the (1) LD_LIBMAP, (2) LD_LIBRARY_PATH, (3) LD_LIBMAP_DISABLE, (4) LD_DEBUG, and (5) LD_ELF_HINTS_PATH environment variables, which allows local users to gain privileges by executing a setuid or setguid program with a modified variable containing an untrusted search path that points to a Trojan horse library, different vectors than CVE-2009-4146.

CPENameOperatorVersion
freebsdeq8.0
freebsdeq7.1

6.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%