CVE Vulnerabilities

CVE-2001-0170

Published: Mar 26, 2001 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files.

Affected Software

NameVendorStart VersionEnd Version
ImmunixImmunix7.0_beta (including)7.0_beta (including)
LinuxConectiva4.0 (including)4.0 (including)
LinuxConectiva4.0es (including)4.0es (including)
LinuxConectiva4.1 (including)4.1 (including)
LinuxConectiva4.2 (including)4.2 (including)
LinuxConectiva5.0 (including)5.0 (including)
LinuxConectiva5.1 (including)5.1 (including)
LinuxConectiva6.0 (including)6.0 (including)
LinuxConectivaecommerce (including)ecommerce (including)
LinuxConectivagraficas (including)graficas (including)
Red Hat Linux 7.0RedHat*

References