CVE-2010-3856
published 2011-01-07CVE-2010-3856: ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment variable to…
PriorityP344high7.2CVSS 2.0
AVLACLAuNCCICAC
EXPLOIT
EPSS
9.45%
94.9th percentile
ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment variable to reference dynamic shared objects (DSOs) as audit objects, which allows local users to gain privileges by leveraging an unsafe DSO located in a trusted library directory, as demonstrated by libpcprofile.so.
Affected
62 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.11.2-8 (bookworm) | glibc 2.11.2-8 (bookworm) |
| gnu | glibc | <= 2.11.2 | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
vendor_ubuntu6.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-87g4-5jq4-wvr2: ld
ghsa_unreviewed·2022-05-14
CVE-2010-3856 [HIGH] GHSA-87g4-5jq4-wvr2: ld
ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment variable to reference dynamic shared objects (DSOs) as audit objects, which allows local users to gain privileges by leveraging an unsafe DSO located in a trusted library directory, as demonstrated by libpcprofile.so.
OSV
CVE-2010-3856: ld
osv·2011-01-07·CVSS 7.2
CVE-2010-3856 [HIGH] CVE-2010-3856: ld
ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment variable to reference dynamic shared objects (DSOs) as audit objects, which allows local users to gain privileges by leveraging an unsafe DSO located in a trusted library directory, as demonstrated by libpcprofile.so.
Ubuntu
GNU C Library vulnerability
vendor_ubuntu·2011-01-12·CVSS 6.9
[MEDIUM] GNU C Library vulnerability
Title: GNU C Library vulnerability
Summary: Privilege escalation via loading of libraries via RPATH DSTs with setuid programs.
USN-1009-1 fixed vulnerabilities in the GNU C library. Colin Watson
discovered that the fixes were incomplete and introduced flaws with
setuid programs loading libraries that used dynamic string tokens in their
RPATH. If the "man" program was installed setuid, a local attacker could
exploit this to gain "man" user privileges, potentially leading to further
privilege escalations. Default Ubuntu installations were not affected.
Original advisory details:
Tavis Ormandy discovered multiple flaws in the GNU C Library's handling
of the LD_AUDIT environment variable when running a privileged binary. A
local attacker could exploit this to gain root privileges. (CVE-201
VMware
VMware ESX third party updates for Service Console packages glibc, sudo, and openldap
vendor_vmware·2011-01-04·CVSS 6.9
CVE-2010-0211 [MEDIUM] VMware ESX third party updates for Service Console packages glibc, sudo, and openldap
VMSA-2011-0001: VMware ESX third party updates for Service Console packages glibc, sudo, and openldap
a. Service Console update for glibc The service console packages glibc, glibc-common, and nscd are each updated to version 2.5-34.4908.vmw. The Common Vulnerabilities and Exposures project ( cve.mitre.org) has assigned the names CVE-2010-3847 and CVE-2010-3856 to the issues addressed in this update. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product ============= Product Version ======= Running on ======= Replace with/ Apply Patch ================= VMware Product ============= VirtualCente Product Version ======= any Running on ======= Windows Replace with/ Apply Patch ================= not a
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2010-10-22·CVSS 6.9
CVE-2010-3847 [MEDIUM] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Local root escalation via LD_AUDIT environment variable.
Tavis Ormandy discovered multiple flaws in the GNU C Library's handling
of the LD_AUDIT environment variable when running a privileged binary. A
local attacker could exploit this to gain root privileges. (CVE-2010-3847,
CVE-2010-3856)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
glibc: ld.so arbitrary DSO loading via LD_AUDIT in setuid/setgid programs
vendor_redhat·2010-10-22·CVSS 7.2
CVE-2010-3856 [HIGH] CWE-426 glibc: ld.so arbitrary DSO loading via LD_AUDIT in setuid/setgid programs
glibc: ld.so arbitrary DSO loading via LD_AUDIT in setuid/setgid programs
ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment variable to reference dynamic shared objects (DSOs) as audit objects, which allows local users to gain privileges by leveraging an unsafe DSO located in a trusted library directory, as demonstrated by libpcprofile.so.
Debian
CVE-2010-3856: glibc - ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before...
vendor_debian·2010·CVSS 7.2
CVE-2010-3856 [HIGH] CVE-2010-3856: glibc - ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before...
ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment variable to reference dynamic shared objects (DSOs) as audit objects, which allows local users to gain privileges by leveraging an unsafe DSO located in a trusted library directory, as demonstrated by libpcprofile.so.
Scope: local
bookworm: resolved (fixed in 2.11.2-8)
bullseye: resolved (fixed in 2.11.2-8)
forky: resolved (fixed in 2.11.2-8)
sid: resolved (fixed in 2.11.2-8)
trixie: resolved (fixed in 2.11.2-8)
No detection rules found.
Exploit-DB
glibc - 'LD_AUDIT' Arbitrary DSO Load Privilege Escalation (Metasploit)
exploitdb·2018-02-12
CVE-2010-3856 glibc - 'LD_AUDIT' Arbitrary DSO Load Privilege Escalation (Metasploit)
glibc - 'LD_AUDIT' Arbitrary DSO Load Privilege Escalation (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core/exploit/local/linux'
require 'msf/core/exploit/exe'
class MetasploitModule 'glibc LD_AUDIT Arbitrary DSO Load Privilege Escalation',
'Description' => %q{
This module attempts to gain root privileges on Linux systems by abusing
a vulnerability in the GNU C Library (glibc) dynamic linker.
glibc ld.so in versions before 2.11.3, and 2.12.x before 2.12.2 does not
properly restrict use of the LD_AUDIT environment variable when loading
setuid executables. This allows loading arbitrary shared objects from
the trusted library search path with the privileges of the s
Exploit-DB
glibc - 'LD_AUDIT' Arbitrary DSO Load Privilege Escalation
exploitdb·2011-11-10·CVSS 7.2
CVE-2010-3856 [HIGH] glibc - 'LD_AUDIT' Arbitrary DSO Load Privilege Escalation
glibc - 'LD_AUDIT' Arbitrary DSO Load Privilege Escalation
---
#!/bin/sh
#######################################################
# I Can't Read and I Won't Race You Either #
# by zx2c4 #
#######################################################
################################################################################
# This is an exploit for CVE-2010-3856.
#
# A while back, Tavis showed us three ways to exploit flaws in glibc's dynamic
# linker involving LD_AUDIT. [1] [2]
#
# The first way involved opening a file descriptor and using fexecve to easily
# win a race with $ORIGIN. The problem was that this required having read
# permissions on the SUID executables. Tavis recommended a work around involving
# filling a pipe until it was full so that anything written to stderr would
#
Exploit-DB
GNU C Library 2.x (libc6) - Dynamic Linker LD_AUDIT Arbitrary DSO Load Privilege Escalation
exploitdb·2010-10-22·CVSS 6.9
CVE-2010-3856 [MEDIUM] GNU C Library 2.x (libc6) - Dynamic Linker LD_AUDIT Arbitrary DSO Load Privilege Escalation
GNU C Library 2.x (libc6) - Dynamic Linker LD_AUDIT Arbitrary DSO Load Privilege Escalation
---
Source: http://marc.info/?l=full-disclosure&m=128776663124692&w=2
The GNU C library dynamic linker will dlopen arbitrary DSOs during setuid loads
Cześć, This advisory describes CVE-2010-3856, an addendum to CVE-2010-3847.
Please see http://seclists.org/fulldisclosure/2010/Oct/257 for background
information.
For obvious reasons, the dynamic linker will ignore requests to preload user
specified libraries for setuid/setgid programs. However, it is possible to
imagine legitimate use cases for this functionality, so the glibc developers
provide an exception to this rule.
LD_PRELOAD
A whitespace-separated list of additional, user-specified, ELF
shared libraries to be loaded before all others
Metasploit
glibc LD_AUDIT Arbitrary DSO Load Privilege Escalation
metasploit
glibc LD_AUDIT Arbitrary DSO Load Privilege Escalation
glibc LD_AUDIT Arbitrary DSO Load Privilege Escalation
This module attempts to gain root privileges on Linux systems by abusing a vulnerability in the GNU C Library (glibc) dynamic linker. glibc ld.so in versions before 2.11.3, and 2.12.x before 2.12.2 does not properly restrict use of the LD_AUDIT environment variable when loading setuid executables. This allows loading arbitrary shared objects from the trusted library search path with the privileges of the suid user. This module uses LD_AUDIT to load the libpcprofile.so shared object, distributed with some versions of glibc, and leverages arbitrary file creation functionality in the library constructor to write a root-owned world-writable file to a system trusted search path (usually /lib). The file is then overwritten with a shared obj
Bugzilla
CVE-2010-3856 glibc: ld.so arbitrary DSO loading via LD_AUDIT in setuid/setgid programs
bugzilla·2010-10-22·CVSS 7.2
CVE-2010-3856 [HIGH] CVE-2010-3856 glibc: ld.so arbitrary DSO loading via LD_AUDIT in setuid/setgid programs
CVE-2010-3856 glibc: ld.so arbitrary DSO loading via LD_AUDIT in setuid/setgid programs
Tavis Ormandy pointed out that glibc does not properly sanitize DSOs that
are loaded using LD_AUDIT facility. Tavis quoted:
In order to be preloaded during the execution of a privileged program, a
library must be setuid and in the trusted library search path. This is a
reasonable design, in order to be loaded a system administrator must brand
a library as safe before it will be loaded across privilege boundaries.
This allows developers who design their programs to operate safely while
running as setuid are able to do so. The same conditions do not apply to
LD_AUDIT, which will load an arbitrary DSOs, regardless of whether it
has been designed to operate safely or not.
Tavis found out that by exploit
Bugzilla
CVE-2010-3856 glibc: ld.so arbitrary DSO loading via LD_AUDIT in setuid/setgid programs [fedora-all]
bugzilla·2010-10-22·CVSS 7.2
CVE-2010-3856 [HIGH] CVE-2010-3856 glibc: ld.so arbitrary DSO loading via LD_AUDIT in setuid/setgid programs [fedora-all]
CVE-2010-3856 glibc: ld.so arbitrary DSO loading via LD_AUDIT in setuid/setgid programs [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=645672
Please note: t
http://packetstormsecurity.com/files/153278/WAGO-852-Industrial-Managed-Switch-Series-Code-Execution-Hardcoded-Credentials.htmlhttp://packetstormsecurity.com/files/173661/OpenSSH-Forwarded-SSH-Agent-Remote-Code-Execution.htmlhttp://seclists.org/fulldisclosure/2010/Oct/344http://seclists.org/fulldisclosure/2019/Jun/18http://seclists.org/fulldisclosure/2023/Jul/31http://secunia.com/advisories/42787http://security.gentoo.org/glsa/glsa-201011-01.xmlhttp://sourceware.org/ml/libc-hacker/2010-10/msg00010.htmlhttp://support.avaya.com/css/P8/documents/100121017http://www.debian.org/security/2010/dsa-2122http://www.mandriva.com/security/advisories?name=MDVSA-2010:212http://www.openwall.com/lists/oss-security/2023/07/19/9http://www.openwall.com/lists/oss-security/2023/07/20/1http://www.redhat.com/support/errata/RHSA-2010-0872.htmlhttp://www.securityfocus.com/archive/1/515545/100/0/threadedhttp://www.securityfocus.com/bid/44347http://www.ubuntu.com/usn/USN-1009-1http://www.vmware.com/security/advisories/VMSA-2011-0001.htmlhttp://www.vupen.com/english/advisories/2011/0025https://bugzilla.redhat.com/show_bug.cgi?id=645672https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00007.htmlhttps://rhn.redhat.com/errata/RHSA-2010-0793.htmlhttps://seclists.org/bugtraq/2019/Jun/14https://www.exploit-db.com/exploits/44025/http://packetstormsecurity.com/files/153278/WAGO-852-Industrial-Managed-Switch-Series-Code-Execution-Hardcoded-Credentials.htmlhttp://packetstormsecurity.com/files/173661/OpenSSH-Forwarded-SSH-Agent-Remote-Code-Execution.htmlhttp://seclists.org/fulldisclosure/2010/Oct/344http://seclists.org/fulldisclosure/2019/Jun/18http://seclists.org/fulldisclosure/2023/Jul/31http://secunia.com/advisories/42787http://security.gentoo.org/glsa/glsa-201011-01.xmlhttp://sourceware.org/ml/libc-hacker/2010-10/msg00010.htmlhttp://support.avaya.com/css/P8/documents/100121017http://www.debian.org/security/2010/dsa-2122http://www.mandriva.com/security/advisories?name=MDVSA-2010:212http://www.openwall.com/lists/oss-security/2023/07/19/9http://www.openwall.com/lists/oss-security/2023/07/20/1http://www.redhat.com/support/errata/RHSA-2010-0872.htmlhttp://www.securityfocus.com/archive/1/515545/100/0/threadedhttp://www.securityfocus.com/bid/44347http://www.ubuntu.com/usn/USN-1009-1http://www.vmware.com/security/advisories/VMSA-2011-0001.htmlhttp://www.vupen.com/english/advisories/2011/0025https://bugzilla.redhat.com/show_bug.cgi?id=645672https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00007.htmlhttps://rhn.redhat.com/errata/RHSA-2010-0793.htmlhttps://seclists.org/bugtraq/2019/Jun/14https://www.exploit-db.com/exploits/44025/
2011-01-07
Published