Secunia
|
|

CVE Reference: CVE-2010-3856 |
|
| NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE. | |
|
Original Page at CVE MITRE: CVE-2010-3856 |
|
|
Description: ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment variable to reference dynamic shared objects (DSOs) as audit objects, which allows local users to gain privileges by leveraging an unsafe DSO located in a trusted library directory, as demonstrated by libpcprofile.so. |
|
|
CVE Status: Candidate |
|
|
References: UBUNTU http://www.ubuntu.com/usn/USN-1009-1 SAID Secunia Advisory: SA42787 REDHAT http://www.redhat.com/support/errata/RHSA-2010-0872.html MLIST http://sourceware.org/ml/libc-hacker/2010-10/msg00010.html MANDRIVA http://www.mandriva.com/security/advisories?name=MDVSA-2010:212 GENTOO http://security.gentoo.org/glsa/glsa-201011-01.xml FULLDISC http://seclists.org/fulldisclosure/2010/Oct/344 DEBIAN http://www.debian.org/security/2010/dsa-2122 CONFIRM http://support.avaya.com/css/P8/documents/100121017 http://www.vmware.com/security/advisories/VMSA-2011-0001.html BUGTRAQ http://www.securityfocus.com/archive/1/archive/1/515545/100/0/threaded BID 44347 |
|
| Return to the previous page. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |