Secunia Logo
 
CVE Reference: CVE-2004-1453
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2004-1453

Description:
GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does not restrict the use of LD_DEBUG for a setuid program, which allows local users to gain sensitive information, such as the list of symbols used by the program.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/17006

SAID
  Secunia Advisory: SA12306

REDHAT
  http://www.redhat.com/support/errata/RHSA-2005-261.html
  http://www.redhat.com/support/errata/RHSA-2005-256.html

MISC
  http://bugs.gentoo.org/show_bug.cgi?id=59526

GENTOO
  http://www.gentoo.org/security/en/glsa/glsa-200408-16.xml

BID
  10963


Return to the previous page.