CVE Vulnerabilities

CVE-2001-0169

Published: Mar 26, 2001 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.

Affected Software

NameVendorStart VersionEnd Version
Mandrake_linuxMandrakesoft6.0 (including)6.0 (including)
Mandrake_linuxMandrakesoft6.1 (including)6.1 (including)
Mandrake_linuxMandrakesoft7.0 (including)7.0 (including)
Mandrake_linuxMandrakesoft7.1 (including)7.1 (including)
Mandrake_linuxMandrakesoft7.2 (including)7.2 (including)
Mandrake_linux_corporate_serverMandrakesoft1.0.1 (including)1.0.1 (including)
LinuxRedhat6.0 (including)6.0 (including)
LinuxRedhat6.1 (including)6.1 (including)
LinuxRedhat6.2 (including)6.2 (including)
Secure_linuxTrustix1.1 (including)1.1 (including)
Secure_linuxTrustix1.2 (including)1.2 (including)
TurbolinuxTurbolinux*6.0.5 (including)
TurbolinuxTurbolinux6.1 (including)6.1 (including)
Red Hat Linux 6.0RedHat*
Red Hat Linux 6.1RedHat*
Red Hat Linux 6.2RedHat*

References