CVE-2011-0536
published 2011-04-08CVE-2011-0536: Multiple untrusted search path vulnerabilities in elf/dl-object.c in certain modified versions of the GNU C Library (aka glibc or libc6), including…
PriorityP427medium6.9CVSS 2.0
AVLACMAuNCCICAC
EXPLOIT
EPSS
0.79%
52.1th percentile
Multiple untrusted search path vulnerabilities in elf/dl-object.c in certain modified versions of the GNU C Library (aka glibc or libc6), including glibc-2.5-49.el5_5.6 and glibc-2.12-1.7.el6_0.3 in Red Hat Enterprise Linux, allow local users to gain privileges via a crafted dynamic shared object (DSO) in a subdirectory of the current working directory during execution of a (1) setuid or (2) setgid program that has $ORIGIN in (a) RPATH or (b) RUNPATH within the program itself or a referenced library. NOTE: this issue exists because of an incorrect fix for CVE-2010-3847.
Affected
64 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | — | — |
| gnu | glibc | <= 2.13 | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_debian6.9LOW
vendor_redhat6.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESX third party updates for Service Console packages glibc and dhcp
vendor_vmware·2011-10-12·CVSS 4.7
CVE-2010-0296 [MEDIUM] VMware ESX third party updates for Service Console packages glibc and dhcp
VMSA-2011-0012: VMware ESX third party updates for Service Console packages glibc and dhcp
a. ESX third party update for Service Console kernel This update takes the console OS kernel package to kernel-2.6.18-238.9.1 which resolves multiple security issues. The Common Vulnerabilities and Exposures project ( cve.mitre.org) has assigned the names CVE-2010-1083, CVE-2010-2492, CVE-2010-2798, CVE-2010-2938, CVE-2010-2942, CVE-2010-2943, CVE-2010-3015, CVE-2010-3066, CVE-2010-3067, CVE-2010-3078, CVE-2010-3086, CVE-2010-3296, CVE-2010-3432, CVE-2010-3442, CVE-2010-3477, CVE-2010-3699, CVE-2010-3858, CVE-2010-3859, CVE-2010-3865, CVE-2010-3876, CVE-2010-3877, CVE-2010-3880, CVE-2010-3904, CVE-2010-4072, CVE-2010-4073, CVE-2010-4075, CVE-2010-4080, CVE-2010-4081, CVE-2010-4083, CVE-2010-4157, CV
Red Hat
glibc: ld.so insecure handling of privileged programs' RPATHs with $ORIGIN
vendor_redhat·2011-01-12·CVSS 6.9
CVE-2011-1658 [MEDIUM] glibc: ld.so insecure handling of privileged programs' RPATHs with $ORIGIN
glibc: ld.so insecure handling of privileged programs' RPATHs with $ORIGIN
ld.so in the GNU C Library (aka glibc or libc6) 2.13 and earlier expands the $ORIGIN dynamic string token when RPATH is composed entirely of this token, which might allow local users to gain privileges by creating a hard link in an arbitrary directory to a (1) setuid or (2) setgid program with this RPATH value, and then executing the program with a crafted value for the LD_PRELOAD environment variable, a different vulnerability than CVE-2010-3847 and CVE-2011-0536. NOTE: it is not expected that any standard operating-system distribution would ship an applicable setuid or setgid program.
Package: glibc (Red Hat Enterprise Linux 4) - Will not fix
Red Hat
glibc: fix causes linker to search CWD when running privileged program with $ORIGIN in R*PATH
vendor_redhat·2011-01-11·CVSS 6.9
CVE-2011-0536 [MEDIUM] CWE-426 glibc: fix causes linker to search CWD when running privileged program with $ORIGIN in R*PATH
glibc: fix causes linker to search CWD when running privileged program with $ORIGIN in R*PATH
Multiple untrusted search path vulnerabilities in elf/dl-object.c in certain modified versions of the GNU C Library (aka glibc or libc6), including glibc-2.5-49.el5_5.6 and glibc-2.12-1.7.el6_0.3 in Red Hat Enterprise Linux, allow local users to gain privileges via a crafted dynamic shared object (DSO) in a subdirectory of the current working directory during execution of a (1) setuid or (2) setgid program that has $ORIGIN in (a) RPATH or (b) RUNPATH within the program itself or a referenced library. NOTE: this issue exists because of an incorrect fix for CVE-2010-3847.
Package: glibc (Red Hat Enterprise Linux 4) - Not affected
Debian
CVE-2011-0536: glibc - Multiple untrusted search path vulnerabilities in elf/dl-object.c in certain mod...
vendor_debian·2011·CVSS 6.9
CVE-2011-0536 [MEDIUM] CVE-2011-0536: glibc - Multiple untrusted search path vulnerabilities in elf/dl-object.c in certain mod...
Multiple untrusted search path vulnerabilities in elf/dl-object.c in certain modified versions of the GNU C Library (aka glibc or libc6), including glibc-2.5-49.el5_5.6 and glibc-2.12-1.7.el6_0.3 in Red Hat Enterprise Linux, allow local users to gain privileges via a crafted dynamic shared object (DSO) in a subdirectory of the current working directory during execution of a (1) setuid or (2) setgid program that has $ORIGIN in (a) RPATH or (b) RUNPATH within the program itself or a referenced library. NOTE: this issue exists because of an incorrect fix for CVE-2010-3847.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-47f6-pj9c-f35v: ld
ghsa_unreviewed·2022-05-14·CVSS 6.9
CVE-2011-1658 [MEDIUM] GHSA-47f6-pj9c-f35v: ld
ld.so in the GNU C Library (aka glibc or libc6) 2.13 and earlier expands the $ORIGIN dynamic string token when RPATH is composed entirely of this token, which might allow local users to gain privileges by creating a hard link in an arbitrary directory to a (1) setuid or (2) setgid program with this RPATH value, and then executing the program with a crafted value for the LD_PRELOAD environment variable, a different vulnerability than CVE-2010-3847 and CVE-2011-0536. NOTE: it is not expected that any standard operating-system distribution would ship an applicable setuid or setgid program.
GHSA
GHSA-3hm4-67xr-p92g: Multiple untrusted search path vulnerabilities in elf/dl-object
ghsa_unreviewed·2022-05-14·CVSS 6.9
CVE-2011-0536 [MEDIUM] GHSA-3hm4-67xr-p92g: Multiple untrusted search path vulnerabilities in elf/dl-object
Multiple untrusted search path vulnerabilities in elf/dl-object.c in certain modified versions of the GNU C Library (aka glibc or libc6), including glibc-2.5-49.el5_5.6 and glibc-2.12-1.7.el6_0.3 in Red Hat Enterprise Linux, allow local users to gain privileges via a crafted dynamic shared object (DSO) in a subdirectory of the current working directory during execution of a (1) setuid or (2) setgid program that has $ORIGIN in (a) RPATH or (b) RUNPATH within the program itself or a referenced library. NOTE: this issue exists because of an incorrect fix for CVE-2010-3847.
No detection rules found.
Bugzilla
CVE-2011-1658 glibc: ld.so insecure handling of privileged programs' RPATHs with $ORIGIN
bugzilla·2011-04-08·CVSS 6.9
CVE-2011-1658 [MEDIUM] CVE-2011-1658 glibc: ld.so insecure handling of privileged programs' RPATHs with $ORIGIN
CVE-2011-1658 glibc: ld.so insecure handling of privileged programs' RPATHs with $ORIGIN
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-1658 to
the following vulnerability:
Name: CVE-2011-1658
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1658
Assigned: 20110408
Reference: http://sourceware.org/bugzilla/show_bug.cgi?id=12393
Reference: https://bugzilla.redhat.com/show_bug.cgi?id=667974
ld.so in the GNU C Library (aka glibc or libc6) 2.13 and earlier
expands the $ORIGIN dynamic string token when RPATH is composed
entirely of this token, which might allow local users to gain
privileges by creating a hard link in an arbitrary directory to a (1)
setuid or (2) setgid program with this RPATH value, and then executing
the program with a crafted value for the
Bugzilla
CVE-2011-0536 glibc: CVE-2010-3847 fix causes linker to search CWD when running privileged program with $ORIGIN in R*PATH
bugzilla·2011-01-07·CVSS 6.9
CVE-2011-0536 [MEDIUM] CVE-2011-0536 glibc: CVE-2010-3847 fix causes linker to search CWD when running privileged program with $ORIGIN in R*PATH
CVE-2011-0536 glibc: CVE-2010-3847 fix causes linker to search CWD when running privileged program with $ORIGIN in R*PATH
Following patch was applied to glibc packages to address dynamic linker privilege escalation issue CVE-2010-3847 (see bug #643306):
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-3847#c26
http://sourceware.org/git/?p=glibc.git;a=commitdiff;h=4b646a51f13fd6816c483fb24c308a13264c6d1a
This change introduced a regression in handling of privileged programs that use $ORIGIN in R*PATH in the binary itself, or any of the depending libraries. When running such privileged program, this issue causes dynamic linker to not expand $ORIGIN in R*PATH and search for additional dynamic objects starting from the current working directory. This could allow a local user to escalate
http://lists.debian.org/debian-security-announce/2011/msg00005.htmlhttp://openwall.com/lists/oss-security/2011/02/01/3http://openwall.com/lists/oss-security/2011/02/03/2http://secunia.com/advisories/43830http://secunia.com/advisories/43989http://secunia.com/advisories/46397http://securitytracker.com/id?1025289http://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=96611391ad8823ba58405325d78cefeae5cdf699http://www.mandriva.com/security/advisories?name=MDVSA-2011:178http://www.redhat.com/support/errata/RHSA-2011-0412.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0413.htmlhttp://www.securityfocus.com/archive/1/520102/100/0/threadedhttp://www.ubuntu.com/usn/USN-1009-2http://www.vmware.com/security/advisories/VMSA-2011-0012.htmlhttp://www.vupen.com/english/advisories/2011/0863https://bugzilla.redhat.com/show_bug.cgi?id=667974https://launchpad.net/bugs/701783https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13086http://lists.debian.org/debian-security-announce/2011/msg00005.htmlhttp://openwall.com/lists/oss-security/2011/02/01/3http://openwall.com/lists/oss-security/2011/02/03/2http://secunia.com/advisories/43830http://secunia.com/advisories/43989http://secunia.com/advisories/46397http://securitytracker.com/id?1025289http://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=96611391ad8823ba58405325d78cefeae5cdf699http://www.mandriva.com/security/advisories?name=MDVSA-2011:178http://www.redhat.com/support/errata/RHSA-2011-0412.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0413.htmlhttp://www.securityfocus.com/archive/1/520102/100/0/threadedhttp://www.ubuntu.com/usn/USN-1009-2http://www.vmware.com/security/advisories/VMSA-2011-0012.htmlhttp://www.vupen.com/english/advisories/2011/0863https://bugzilla.redhat.com/show_bug.cgi?id=667974https://launchpad.net/bugs/701783https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13086
2011-04-08
Published