Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24481
HistoryApr 10, 2020 - 12:55 a.m.

Privilege Escalation

2020-04-1000:55:25
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.001 Low

EPSS

Percentile

31.1%

glibc is vulnerable to privilege escalation. The fix for CVE-2010-3847 introduced a regression in the way the dynamic loader expanded the $ORIGIN dynamic string token specified in the RPATH and RUNPATH entries in the ELF library header. A local attacker could use this flaw to escalate their privileges via a setuid or setgid program using such a library.

References