LOW · 2.1

CVE-2001-0169

When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to ...

Vulnerability Description

When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
MandrakesoftMandrake Linux6.0
MandrakesoftMandrake Linux Corporate Server1.0.1
RedhatLinux6.0
TrustixSecure Linux1.1
TurbolinuxTurbolinux<= 6.0.5

References

FAQ

What is CVE-2001-0169?

CVE-2001-0169 is a vulnerability with a CVSS score of 2.1 (LOW). When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to ...

How severe is CVE-2001-0169?

CVE-2001-0169 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2001-0169?

Check the references section above for vendor advisories and patch information. Affected products include: Mandrakesoft Mandrake Linux, Mandrakesoft Mandrake Linux Corporate Server, Redhat Linux, Trustix Secure Linux, Turbolinux Turbolinux.