Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:18224
HistoryMay 02, 2019 - 6:35 a.m.

Arbitrary Code Execution

2019-05-0206:35:59
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.0004 Low

EPSS

Percentile

10.1%

GNU C Library is vulnerable to arbitrary code execution. An attacker could use the unsanitized LD_POINTER_GUARD environment variable to bypass the pointer guarding protection on set-user-ID or set-group-ID programs to execute arbitrary code with the permissions of the user running the application. Affected is the function process_envvars of the file elf/rtld.c.

References