CVE-2001-0169
published 2001-03-26CVE-2001-0169: When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also…
PriorityP414low2.1CVSS 2.0
AVLACLAuNCNIPAN
EXPLOIT
EPSS
0.86%
54.5th percentile
When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux_corporate_server | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| redhat | linux | — | — |
| trustix | secure_linux | — | — |
| trustix | secure_linux | — | — |
| turbolinux | turbolinux | <= 6.0.5 | — |
| turbolinux | turbolinux | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat2.1LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2001-01-16·CVSS 2.1
CVE-2001-0169 [LOW] security flaw
security flaw
When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.
GHSA
GHSA-r94v-226p-r77g: When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld
ghsa_unreviewed·2022-04-30
CVE-2001-0169 [LOW] GHSA-r94v-226p-r77g: When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld
When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.
No detection rules found.
http://archives.neohapsis.com/archives/linux/turbolinux/2001-q1/0004.htmlhttp://www.calderasystems.com/support/security/advisories/CSSA-2001-007.0.txthttp://www.debian.org/security/2001/dsa-039http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-012.php3?dis=7.2http://www.novell.com/linux/security/advisories/2001_001_glibc_txt.htmlhttp://www.redhat.com/support/errata/RHSA-2001-002.htmlhttp://www.securityfocus.com/archive/1/157650http://www.securityfocus.com/bid/2223https://exchange.xforce.ibmcloud.com/vulnerabilities/5971http://archives.neohapsis.com/archives/linux/turbolinux/2001-q1/0004.htmlhttp://www.calderasystems.com/support/security/advisories/CSSA-2001-007.0.txthttp://www.debian.org/security/2001/dsa-039http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-012.php3?dis=7.2http://www.novell.com/linux/security/advisories/2001_001_glibc_txt.htmlhttp://www.redhat.com/support/errata/RHSA-2001-002.htmlhttp://www.securityfocus.com/archive/1/157650http://www.securityfocus.com/bid/2223https://exchange.xforce.ibmcloud.com/vulnerabilities/5971
2001-03-26
Published