CVE-2010-3856

Priority
High
Description
ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x
before 2.12.2, does not properly restrict use of the LD_AUDIT environment
variable to reference dynamic shared objects (DSOs) as audit objects, which
allows local users to gain privileges by leveraging an unsafe DSO located
in a trusted library directory, as demonstrated by libpcprofile.so.
References
Assigned-to
kees
Package
Source: glibc (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 8.04 LTS (Hardy Heron):released (2.7-10ubuntu7)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 11.04 (Natty Narwhal):DNE
Package
Upstream:needs-triage
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):released (2.11.1-0ubuntu7.5)
Ubuntu 11.04 (Natty Narwhal):not-affected
More Information

Valid XHTML 1.0 Strict

Updated: 2012-06-01 15:21:29 UTC (commit 5347)