CVE-2011-1095
published 2011-04-10CVE-2011-1095: locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not quote its output, which might allow local users to gain…
PriorityP423medium6.2CVSS 2.0
AVLACHAuNCCICAC
EPSS
0.52%
41.0th percentile
locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not quote its output, which might allow local users to gain privileges via a crafted localization environment variable, in conjunction with a program that executes a script that uses the eval function.
Affected
65 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.13-16 (bookworm) | glibc 2.13-16 (bookworm) |
| gnu | glibc | <= 2.12.2 | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
CVSS provenance
nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
osv6.2MEDIUM
vendor_ubuntu6.8MEDIUM
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2012-03-09·CVSS 6.8
CVE-2009-5029 [MEDIUM] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Multiple vulnerabilities were discovered and fixed in the GNU C Library.
It was discovered that the GNU C Library did not properly handle
integer overflows in the timezone handling code. An attacker could use
this to possibly execute arbitrary code by convincing an application
to load a maliciously constructed tzfile. (CVE-2009-5029)
It was discovered that the GNU C Library did not properly handle
passwd.adjunct.byname map entries in the Network Information Service
(NIS) code in the name service caching daemon (nscd). An attacker
could use this to obtain the encrypted passwords of NIS accounts.
This issue only affected Ubuntu 8.04 LTS. (CVE-2010-0015)
Chris Evans reported that the GNU C Library did not properly
calculate the amount of memor
VMware
VMware ESX third party updates for Service Console packages glibc and dhcp
vendor_vmware·2011-10-12·CVSS 4.7
CVE-2010-0296 [MEDIUM] VMware ESX third party updates for Service Console packages glibc and dhcp
VMSA-2011-0012: VMware ESX third party updates for Service Console packages glibc and dhcp
a. ESX third party update for Service Console kernel This update takes the console OS kernel package to kernel-2.6.18-238.9.1 which resolves multiple security issues. The Common Vulnerabilities and Exposures project ( cve.mitre.org) has assigned the names CVE-2010-1083, CVE-2010-2492, CVE-2010-2798, CVE-2010-2938, CVE-2010-2942, CVE-2010-2943, CVE-2010-3015, CVE-2010-3066, CVE-2010-3067, CVE-2010-3078, CVE-2010-3086, CVE-2010-3296, CVE-2010-3432, CVE-2010-3442, CVE-2010-3477, CVE-2010-3699, CVE-2010-3858, CVE-2010-3859, CVE-2010-3865, CVE-2010-3876, CVE-2010-3877, CVE-2010-3880, CVE-2010-3904, CVE-2010-4072, CVE-2010-4073, CVE-2010-4075, CVE-2010-4080, CVE-2010-4081, CVE-2010-4083, CVE-2010-4157, CV
Debian
CVE-2011-1095: glibc - locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) bef...
vendor_debian·2011·CVSS 6.2
CVE-2011-1095 [MEDIUM] CVE-2011-1095: glibc - locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) bef...
locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not quote its output, which might allow local users to gain privileges via a crafted localization environment variable, in conjunction with a program that executes a script that uses the eval function.
Scope: local
bookworm: resolved (fixed in 2.13-16)
bullseye: resolved (fixed in 2.13-16)
forky: resolved (fixed in 2.13-16)
sid: resolved (fixed in 2.13-16)
trixie: resolved (fixed in 2.13-16)
Red Hat
glibc: insufficient quoting in the locale command output
vendor_redhat·2010-08-11·CVSS 6.2
CVE-2011-1095 [MEDIUM] glibc: insufficient quoting in the locale command output
glibc: insufficient quoting in the locale command output
locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not quote its output, which might allow local users to gain privileges via a crafted localization environment variable, in conjunction with a program that executes a script that uses the eval function.
GHSA
GHSA-hhjf-9w4x-vhhf: locale/programs/locale
ghsa_unreviewed·2022-05-14
CVE-2011-1095 [MEDIUM] GHSA-hhjf-9w4x-vhhf: locale/programs/locale
locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not quote its output, which might allow local users to gain privileges via a crafted localization environment variable, in conjunction with a program that executes a script that uses the eval function.
OSV
CVE-2011-1095: locale/programs/locale
osv·2011-04-10·CVSS 6.2
CVE-2011-1095 [MEDIUM] CVE-2011-1095: locale/programs/locale
locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not quote its output, which might allow local users to gain privileges via a crafted localization environment variable, in conjunction with a program that executes a script that uses the eval function.
No detection rules found.
No public exploits indexed.
http://bugs.gentoo.org/show_bug.cgi?id=330923http://openwall.com/lists/oss-security/2011/03/08/21http://openwall.com/lists/oss-security/2011/03/08/22http://openwall.com/lists/oss-security/2011/03/08/8http://secunia.com/advisories/43830http://secunia.com/advisories/43976http://secunia.com/advisories/43989http://secunia.com/advisories/46397http://security.gentoo.org/glsa/glsa-201011-01.xmlhttp://securitytracker.com/id?1025286http://sources.redhat.com/bugzilla/show_bug.cgi?id=11904http://sourceware.org/bugzilla/show_bug.cgi?id=11904http://sourceware.org/git/?p=glibc.git%3Ba=patch%3Bh=026373745eab50a683536d950cb7e17dc98c4259http://www.mandriva.com/security/advisories?name=MDVSA-2011:178http://www.redhat.com/support/errata/RHSA-2011-0412.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0413.htmlhttp://www.securityfocus.com/archive/1/520102/100/0/threadedhttp://www.vmware.com/security/advisories/VMSA-2011-0012.htmlhttp://www.vupen.com/english/advisories/2011/0863https://bugzilla.redhat.com/show_bug.cgi?id=625893https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12272http://bugs.gentoo.org/show_bug.cgi?id=330923http://openwall.com/lists/oss-security/2011/03/08/21http://openwall.com/lists/oss-security/2011/03/08/22http://openwall.com/lists/oss-security/2011/03/08/8http://secunia.com/advisories/43830http://secunia.com/advisories/43976http://secunia.com/advisories/43989http://secunia.com/advisories/46397http://security.gentoo.org/glsa/glsa-201011-01.xmlhttp://securitytracker.com/id?1025286http://sources.redhat.com/bugzilla/show_bug.cgi?id=11904http://sourceware.org/bugzilla/show_bug.cgi?id=11904http://sourceware.org/git/?p=glibc.git%3Ba=patch%3Bh=026373745eab50a683536d950cb7e17dc98c4259http://www.mandriva.com/security/advisories?name=MDVSA-2011:178http://www.redhat.com/support/errata/RHSA-2011-0412.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0413.htmlhttp://www.securityfocus.com/archive/1/520102/100/0/threadedhttp://www.vmware.com/security/advisories/VMSA-2011-0012.htmlhttp://www.vupen.com/english/advisories/2011/0863https://bugzilla.redhat.com/show_bug.cgi?id=625893https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12272
2011-04-10
Published