CVE-2010-3847
published 2011-01-07CVE-2010-3847: elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the…
PriorityP347medium6.9CVSS 2.0
AVLACMAuNCCICAC
EXPLOIT
EPSS
8.75%
94.6th percentile
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via a crafted dynamic shared object (DSO) located in an arbitrary directory.
Affected
69 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.11.2-8 (bookworm) | glibc 2.11.2-8 (bookworm) |
| debian | glibc | — | — |
| gnu | glibc | <= 2.13 | — |
| gnu | glibc | <= 2.11.2 | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
vendor_ubuntu6.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
glibc: ld.so insecure handling of privileged programs' RPATHs with $ORIGIN
vendor_redhat·2011-01-12·CVSS 6.9
CVE-2011-1658 [MEDIUM] glibc: ld.so insecure handling of privileged programs' RPATHs with $ORIGIN
glibc: ld.so insecure handling of privileged programs' RPATHs with $ORIGIN
ld.so in the GNU C Library (aka glibc or libc6) 2.13 and earlier expands the $ORIGIN dynamic string token when RPATH is composed entirely of this token, which might allow local users to gain privileges by creating a hard link in an arbitrary directory to a (1) setuid or (2) setgid program with this RPATH value, and then executing the program with a crafted value for the LD_PRELOAD environment variable, a different vulnerability than CVE-2010-3847 and CVE-2011-0536. NOTE: it is not expected that any standard operating-system distribution would ship an applicable setuid or setgid program.
Package: glibc (Red Hat Enterprise Linux 4) - Will not fix
Ubuntu
GNU C Library vulnerability
vendor_ubuntu·2011-01-12·CVSS 6.9
[MEDIUM] GNU C Library vulnerability
Title: GNU C Library vulnerability
Summary: Privilege escalation via loading of libraries via RPATH DSTs with setuid programs.
USN-1009-1 fixed vulnerabilities in the GNU C library. Colin Watson
discovered that the fixes were incomplete and introduced flaws with
setuid programs loading libraries that used dynamic string tokens in their
RPATH. If the "man" program was installed setuid, a local attacker could
exploit this to gain "man" user privileges, potentially leading to further
privilege escalations. Default Ubuntu installations were not affected.
Original advisory details:
Tavis Ormandy discovered multiple flaws in the GNU C Library's handling
of the LD_AUDIT environment variable when running a privileged binary. A
local attacker could exploit this to gain root privileges. (CVE-201
Red Hat
glibc: fix causes linker to search CWD when running privileged program with $ORIGIN in R*PATH
vendor_redhat·2011-01-11·CVSS 6.9
CVE-2011-0536 [MEDIUM] CWE-426 glibc: fix causes linker to search CWD when running privileged program with $ORIGIN in R*PATH
glibc: fix causes linker to search CWD when running privileged program with $ORIGIN in R*PATH
Multiple untrusted search path vulnerabilities in elf/dl-object.c in certain modified versions of the GNU C Library (aka glibc or libc6), including glibc-2.5-49.el5_5.6 and glibc-2.12-1.7.el6_0.3 in Red Hat Enterprise Linux, allow local users to gain privileges via a crafted dynamic shared object (DSO) in a subdirectory of the current working directory during execution of a (1) setuid or (2) setgid program that has $ORIGIN in (a) RPATH or (b) RUNPATH within the program itself or a referenced library. NOTE: this issue exists because of an incorrect fix for CVE-2010-3847.
Package: glibc (Red Hat Enterprise Linux 4) - Not affected
VMware
VMware ESX third party updates for Service Console packages glibc, sudo, and openldap
vendor_vmware·2011-01-04·CVSS 6.9
CVE-2010-0211 [MEDIUM] VMware ESX third party updates for Service Console packages glibc, sudo, and openldap
VMSA-2011-0001: VMware ESX third party updates for Service Console packages glibc, sudo, and openldap
a. Service Console update for glibc The service console packages glibc, glibc-common, and nscd are each updated to version 2.5-34.4908.vmw. The Common Vulnerabilities and Exposures project ( cve.mitre.org) has assigned the names CVE-2010-3847 and CVE-2010-3856 to the issues addressed in this update. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product ============= Product Version ======= Running on ======= Replace with/ Apply Patch ================= VMware Product ============= VirtualCente Product Version ======= any Running on ======= Windows Replace with/ Apply Patch ================= not a
Debian
CVE-2011-0536: glibc - Multiple untrusted search path vulnerabilities in elf/dl-object.c in certain mod...
vendor_debian·2011·CVSS 6.9
CVE-2011-0536 [MEDIUM] CVE-2011-0536: glibc - Multiple untrusted search path vulnerabilities in elf/dl-object.c in certain mod...
Multiple untrusted search path vulnerabilities in elf/dl-object.c in certain modified versions of the GNU C Library (aka glibc or libc6), including glibc-2.5-49.el5_5.6 and glibc-2.12-1.7.el6_0.3 in Red Hat Enterprise Linux, allow local users to gain privileges via a crafted dynamic shared object (DSO) in a subdirectory of the current working directory during execution of a (1) setuid or (2) setgid program that has $ORIGIN in (a) RPATH or (b) RUNPATH within the program itself or a referenced library. NOTE: this issue exists because of an incorrect fix for CVE-2010-3847.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2010-10-22·CVSS 6.9
CVE-2010-3847 [MEDIUM] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Local root escalation via LD_AUDIT environment variable.
Tavis Ormandy discovered multiple flaws in the GNU C Library's handling
of the LD_AUDIT environment variable when running a privileged binary. A
local attacker could exploit this to gain root privileges. (CVE-2010-3847,
CVE-2010-3856)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
glibc: ld.so insecure handling of $ORIGIN in LD_AUDIT for setuid/setgid programs
vendor_redhat·2010-10-18·CVSS 6.9
CVE-2010-3847 [MEDIUM] CWE-426 glibc: ld.so insecure handling of $ORIGIN in LD_AUDIT for setuid/setgid programs
glibc: ld.so insecure handling of $ORIGIN in LD_AUDIT for setuid/setgid programs
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via a crafted dynamic shared object (DSO) located in an arbitrary directory.
Debian
CVE-2010-3847: glibc - elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2,...
vendor_debian·2010·CVSS 6.9
CVE-2010-3847 [MEDIUM] CVE-2010-3847: glibc - elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2,...
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via a crafted dynamic shared object (DSO) located in an arbitrary directory.
Scope: local
bookworm: resolved (fixed in 2.11.2-8)
bullseye: resolved (fixed in 2.11.2-8)
forky: resolved (fixed in 2.11.2-8)
sid: resolved (fixed in 2.11.2-8)
trixie: resolved (fixed in 2.11.2-8)
GHSA
GHSA-q3fw-v7x4-w8hh: elf/dl-load
ghsa_unreviewed·2022-05-14
CVE-2010-3847 [MEDIUM] CWE-59 GHSA-q3fw-v7x4-w8hh: elf/dl-load
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via a crafted dynamic shared object (DSO) located in an arbitrary directory.
GHSA
GHSA-47f6-pj9c-f35v: ld
ghsa_unreviewed·2022-05-14·CVSS 6.9
CVE-2011-1658 [MEDIUM] GHSA-47f6-pj9c-f35v: ld
ld.so in the GNU C Library (aka glibc or libc6) 2.13 and earlier expands the $ORIGIN dynamic string token when RPATH is composed entirely of this token, which might allow local users to gain privileges by creating a hard link in an arbitrary directory to a (1) setuid or (2) setgid program with this RPATH value, and then executing the program with a crafted value for the LD_PRELOAD environment variable, a different vulnerability than CVE-2010-3847 and CVE-2011-0536. NOTE: it is not expected that any standard operating-system distribution would ship an applicable setuid or setgid program.
GHSA
GHSA-3hm4-67xr-p92g: Multiple untrusted search path vulnerabilities in elf/dl-object
ghsa_unreviewed·2022-05-14·CVSS 6.9
CVE-2011-0536 [MEDIUM] GHSA-3hm4-67xr-p92g: Multiple untrusted search path vulnerabilities in elf/dl-object
Multiple untrusted search path vulnerabilities in elf/dl-object.c in certain modified versions of the GNU C Library (aka glibc or libc6), including glibc-2.5-49.el5_5.6 and glibc-2.12-1.7.el6_0.3 in Red Hat Enterprise Linux, allow local users to gain privileges via a crafted dynamic shared object (DSO) in a subdirectory of the current working directory during execution of a (1) setuid or (2) setgid program that has $ORIGIN in (a) RPATH or (b) RUNPATH within the program itself or a referenced library. NOTE: this issue exists because of an incorrect fix for CVE-2010-3847.
OSV
CVE-2010-3847: elf/dl-load
osv·2011-01-07·CVSS 6.9
CVE-2010-3847 [MEDIUM] CVE-2010-3847: elf/dl-load
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via a crafted dynamic shared object (DSO) located in an arbitrary directory.
No detection rules found.
Exploit-DB
glibc - '$ORIGIN' Expansion Privilege Escalation (Metasploit)
exploitdb·2018-02-12
CVE-2010-3847 glibc - '$ORIGIN' Expansion Privilege Escalation (Metasploit)
glibc - '$ORIGIN' Expansion Privilege Escalation (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core/exploit/local/linux'
require 'msf/core/exploit/exe'
class MetasploitModule "glibc '$ORIGIN' Expansion Privilege Escalation",
'Description' => %q{
This module attempts to gain root privileges on Linux systems by abusing
a vulnerability in the GNU C Library (glibc) dynamic linker.
glibc ld.so in versions before 2.11.3, and 2.12.x before 2.12.2 does not
properly restrict use of the LD_AUDIT environment variable when loading
setuid executables which allows control over the $ORIGIN library search
path resulting in execution of arbitrary shared objects.
This module opens
Exploit-DB
glibc - 'LD_AUDIT' Arbitrary DSO Load Privilege Escalation (Metasploit)
exploitdb·2018-02-12
CVE-2010-3856 glibc - 'LD_AUDIT' Arbitrary DSO Load Privilege Escalation (Metasploit)
glibc - 'LD_AUDIT' Arbitrary DSO Load Privilege Escalation (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core/exploit/local/linux'
require 'msf/core/exploit/exe'
class MetasploitModule 'glibc LD_AUDIT Arbitrary DSO Load Privilege Escalation',
'Description' => %q{
This module attempts to gain root privileges on Linux systems by abusing
a vulnerability in the GNU C Library (glibc) dynamic linker.
glibc ld.so in versions before 2.11.3, and 2.12.x before 2.12.2 does not
properly restrict use of the LD_AUDIT environment variable when loading
setuid executables. This allows loading arbitrary shared objects from
the trusted library search path with the privileges of the s
Exploit-DB
GNU C Library 2.x (libc6) - Dynamic Linker LD_AUDIT Arbitrary DSO Load Privilege Escalation
exploitdb·2010-10-22·CVSS 6.9
CVE-2010-3856 [MEDIUM] GNU C Library 2.x (libc6) - Dynamic Linker LD_AUDIT Arbitrary DSO Load Privilege Escalation
GNU C Library 2.x (libc6) - Dynamic Linker LD_AUDIT Arbitrary DSO Load Privilege Escalation
---
Source: http://marc.info/?l=full-disclosure&m=128776663124692&w=2
The GNU C library dynamic linker will dlopen arbitrary DSOs during setuid loads
Cześć, This advisory describes CVE-2010-3856, an addendum to CVE-2010-3847.
Please see http://seclists.org/fulldisclosure/2010/Oct/257 for background
information.
For obvious reasons, the dynamic linker will ignore requests to preload user
specified libraries for setuid/setgid programs. However, it is possible to
imagine legitimate use cases for this functionality, so the glibc developers
provide an exception to this rule.
LD_PRELOAD
A whitespace-separated list of additional, user-specified, ELF
shared libraries to be loaded before all others
Exploit-DB
GNU C library dynamic linker - '$ORIGIN' Expansion
exploitdb·2010-10-18·CVSS 6.9
CVE-2011-0536 [MEDIUM] GNU C library dynamic linker - '$ORIGIN' Expansion
GNU C library dynamic linker - '$ORIGIN' Expansion
---
from: http://marc.info/?l=full-disclosure&m=128739684614072&w=2
The GNU C library dynamic linker expands $ORIGIN in setuid library search path
Gruezi, This is CVE-2010-3847.
The dynamic linker (or dynamic loader) is responsible for the runtime linking of
dynamically linked programs. ld.so operates in two security modes, a permissive
mode that allows a high degree of control over the load operation, and a secure
mode (libc_enable_secure) intended to prevent users from interfering with the
loading of privileged executables.
$ORIGIN is an ELF substitution sequence representing the location of the
executable being loaded in the filesystem hierarchy. The intention is to allow
executables to specify a search path for libraries that is
Metasploit
glibc LD_AUDIT Arbitrary DSO Load Privilege Escalation
metasploit
glibc LD_AUDIT Arbitrary DSO Load Privilege Escalation
glibc LD_AUDIT Arbitrary DSO Load Privilege Escalation
This module attempts to gain root privileges on Linux systems by abusing a vulnerability in the GNU C Library (glibc) dynamic linker. glibc ld.so in versions before 2.11.3, and 2.12.x before 2.12.2 does not properly restrict use of the LD_AUDIT environment variable when loading setuid executables. This allows loading arbitrary shared objects from the trusted library search path with the privileges of the suid user. This module uses LD_AUDIT to load the libpcprofile.so shared object, distributed with some versions of glibc, and leverages arbitrary file creation functionality in the library constructor to write a root-owned world-writable file to a system trusted search path (usually /lib). The file is then overwritten with a shared obj
Metasploit
glibc '$ORIGIN' Expansion Privilege Escalation
metasploit
glibc '$ORIGIN' Expansion Privilege Escalation
glibc '$ORIGIN' Expansion Privilege Escalation
This module attempts to gain root privileges on Linux systems by abusing a vulnerability in the GNU C Library (glibc) dynamic linker. glibc `ld.so` versions before 2.11.3, and 2.12.x before 2.12.2 does not properly restrict use of the `LD_AUDIT` environment variable when loading setuid executables which allows control over the `$ORIGIN` library search path resulting in execution of arbitrary shared objects. This module opens a file descriptor to the specified suid executable via a hard link, then replaces the hard link with a shared object before instructing the linker to execute the file descriptor, resulting in arbitrary code execution. The specified setuid binary must be readable and located on the same file system partition as the specifi
Bugzilla
CVE-2011-1658 glibc: ld.so insecure handling of privileged programs' RPATHs with $ORIGIN
bugzilla·2011-04-08·CVSS 6.9
CVE-2011-1658 [MEDIUM] CVE-2011-1658 glibc: ld.so insecure handling of privileged programs' RPATHs with $ORIGIN
CVE-2011-1658 glibc: ld.so insecure handling of privileged programs' RPATHs with $ORIGIN
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-1658 to
the following vulnerability:
Name: CVE-2011-1658
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1658
Assigned: 20110408
Reference: http://sourceware.org/bugzilla/show_bug.cgi?id=12393
Reference: https://bugzilla.redhat.com/show_bug.cgi?id=667974
ld.so in the GNU C Library (aka glibc or libc6) 2.13 and earlier
expands the $ORIGIN dynamic string token when RPATH is composed
entirely of this token, which might allow local users to gain
privileges by creating a hard link in an arbitrary directory to a (1)
setuid or (2) setgid program with this RPATH value, and then executing
the program with a crafted value for the
Bugzilla
CVE-2011-0536 glibc: CVE-2010-3847 fix causes linker to search CWD when running privileged program with $ORIGIN in R*PATH
bugzilla·2011-01-07·CVSS 6.9
CVE-2011-0536 [MEDIUM] CVE-2011-0536 glibc: CVE-2010-3847 fix causes linker to search CWD when running privileged program with $ORIGIN in R*PATH
CVE-2011-0536 glibc: CVE-2010-3847 fix causes linker to search CWD when running privileged program with $ORIGIN in R*PATH
Following patch was applied to glibc packages to address dynamic linker privilege escalation issue CVE-2010-3847 (see bug #643306):
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-3847#c26
http://sourceware.org/git/?p=glibc.git;a=commitdiff;h=4b646a51f13fd6816c483fb24c308a13264c6d1a
This change introduced a regression in handling of privileged programs that use $ORIGIN in R*PATH in the binary itself, or any of the depending libraries. When running such privileged program, this issue causes dynamic linker to not expand $ORIGIN in R*PATH and search for additional dynamic objects starting from the current working directory. This could allow a local user to escalate
Bugzilla
CVE-2010-3847 glibc: ld.so insecure handling of $ORIGIN in LD_AUDIT for setuid/setgid programs [fedora-all]
bugzilla·2010-10-18·CVSS 6.9
CVE-2010-3847 [MEDIUM] CVE-2010-3847 glibc: ld.so insecure handling of $ORIGIN in LD_AUDIT for setuid/setgid programs [fedora-all]
CVE-2010-3847 glibc: ld.so insecure handling of $ORIGIN in LD_AUDIT for setuid/setgid programs [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=643306
Please
Bugzilla
CVE-2010-3847 glibc: ld.so insecure handling of $ORIGIN in LD_AUDIT for setuid/setgid programs
bugzilla·2010-10-15·CVSS 6.9
CVE-2010-3847 [MEDIUM] CVE-2010-3847 glibc: ld.so insecure handling of $ORIGIN in LD_AUDIT for setuid/setgid programs
CVE-2010-3847 glibc: ld.so insecure handling of $ORIGIN in LD_AUDIT for setuid/setgid programs
Tavis Ormandy pointed out that glibc does not follow ELF specification recommendation that $ORIGIN expansion should not be performed for setuid/setgid programs. Tavis quoted:
http://web.archive.org/web/20041026003725/http://www.caldera.com/developers/gabi/2003-12-17/ch5.dynamic.html
For security, the dynamic linker does not allow use of $ORIGIN substitution
sequences for set-user and set-group ID programs. For such sequences that
appear within strings specified by DT_RUNPATH dynamic array entries, the
specific search path containing the $ORIGIN sequence is ignored (though other
search paths in the same string are processed). $ORIGIN sequences within a
DT_NEEDED entry or path passed as a parame
Bugzilla
CVE-2007-3847 httpd: out of bounds read
bugzilla·2007-08-03·CVSS 5.0
CVE-2007-3847 [MEDIUM] CVE-2007-3847 httpd: out of bounds read
CVE-2007-3847 httpd: out of bounds read
A buffer "over-read" flaw was found in Apache httpd used for caching. This
allows a malicious origin server to possibly cause a process crash on a caching
forward proxy, which is a DoS for a threaded MPM on httpd 2.0+
On httpd 1.3 this would cause a client crash but this is not considered a
security issue as httpd would continue to run and spawn new children as required.
http://marc.info/?l=apache-httpd-dev&m=118595556504202&w=2
Discussion:
This issue has been addressed in following products:
Red Hat Certificate System 7.3
Via RHSA-2010:0602 https://rhn.redhat.com/errata/RHSA-2010-0602.html
http://seclists.org/fulldisclosure/2010/Oct/257http://seclists.org/fulldisclosure/2010/Oct/292http://seclists.org/fulldisclosure/2010/Oct/294http://secunia.com/advisories/42787http://security.gentoo.org/glsa/glsa-201011-01.xmlhttp://sourceware.org/ml/libc-hacker/2010-10/msg00007.htmlhttp://support.avaya.com/css/P8/documents/100120941http://www.debian.org/security/2010/dsa-2122http://www.kb.cert.org/vuls/id/537223http://www.mandriva.com/security/advisories?name=MDVSA-2010:207http://www.redhat.com/support/errata/RHSA-2010-0872.htmlhttp://www.securityfocus.com/archive/1/515545/100/0/threadedhttp://www.securityfocus.com/bid/44154http://www.ubuntu.com/usn/USN-1009-1http://www.vmware.com/security/advisories/VMSA-2011-0001.htmlhttp://www.vupen.com/english/advisories/2011/0025https://bugzilla.redhat.com/show_bug.cgi?id=643306https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00007.htmlhttps://rhn.redhat.com/errata/RHSA-2010-0787.htmlhttps://www.exploit-db.com/exploits/44024/https://www.exploit-db.com/exploits/44025/http://seclists.org/fulldisclosure/2010/Oct/257http://seclists.org/fulldisclosure/2010/Oct/292http://seclists.org/fulldisclosure/2010/Oct/294http://secunia.com/advisories/42787http://security.gentoo.org/glsa/glsa-201011-01.xmlhttp://sourceware.org/ml/libc-hacker/2010-10/msg00007.htmlhttp://support.avaya.com/css/P8/documents/100120941http://www.debian.org/security/2010/dsa-2122http://www.kb.cert.org/vuls/id/537223http://www.mandriva.com/security/advisories?name=MDVSA-2010:207http://www.redhat.com/support/errata/RHSA-2010-0872.htmlhttp://www.securityfocus.com/archive/1/515545/100/0/threadedhttp://www.securityfocus.com/bid/44154http://www.ubuntu.com/usn/USN-1009-1http://www.vmware.com/security/advisories/VMSA-2011-0001.htmlhttp://www.vupen.com/english/advisories/2011/0025https://bugzilla.redhat.com/show_bug.cgi?id=643306https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00007.htmlhttps://rhn.redhat.com/errata/RHSA-2010-0787.htmlhttps://www.exploit-db.com/exploits/44024/https://www.exploit-db.com/exploits/44025/
2011-01-07
Published