cbcvebase.
CVE-2004-1453
published 2004-12-31

CVE-2004-1453: GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does not restrict the use of LD_DEBUG for a setuid program…

low2.1CVSS 3.1
AVLACLAuNCPINAN
GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does not restrict the use of LD_DEBUG for a setuid program, which allows local users to gain sensitive information, such as the list of symbols used by the program.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianglibc< glibc 2.3.5 (bookworm)glibc 2.3.5 (bookworm)
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc
gnuglibc

CVSS provenance

nvd2.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv2.1LOW