glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Immunix | Immunix | 7.0_beta (including) | 7.0_beta (including) |
Linux | Conectiva | 4.0 (including) | 4.0 (including) |
Linux | Conectiva | 4.0es (including) | 4.0es (including) |
Linux | Conectiva | 4.1 (including) | 4.1 (including) |
Linux | Conectiva | 4.2 (including) | 4.2 (including) |
Linux | Conectiva | 5.0 (including) | 5.0 (including) |
Linux | Conectiva | 5.1 (including) | 5.1 (including) |
Linux | Conectiva | 6.0 (including) | 6.0 (including) |
Linux | Conectiva | ecommerce (including) | ecommerce (including) |
Linux | Conectiva | graficas (including) | graficas (including) |
Red Hat Linux 7.0 | RedHat | * |