Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24454
HistoryApr 10, 2020 - 12:54 a.m.

Denial Of Service (DoS)

2020-04-1000:54:45
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.001 Low

EPSS

Percentile

31.1%

glibc is vulnerable to privilege escalation. It was discovered that the glibc dynamic linker/loader did not handle the $ORIGIN dynamic string token set in the LD_AUDIT environment variable securely. A local attacker with write access to a file system containing setuid or setgid binaries could use this flaw to escalate their privileges.

References