CVE Vulnerabilities

CVE-2001-0170

Published: Mar 26, 2001 | Modified: Oct 10, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files.

Affected Software

Name Vendor Start Version End Version
Immunix Immunix 7.0_beta (including) 7.0_beta (including)
Linux Conectiva 4.0 (including) 4.0 (including)
Linux Conectiva 4.0es (including) 4.0es (including)
Linux Conectiva 4.1 (including) 4.1 (including)
Linux Conectiva 4.2 (including) 4.2 (including)
Linux Conectiva 5.0 (including) 5.0 (including)
Linux Conectiva 5.1 (including) 5.1 (including)
Linux Conectiva 6.0 (including) 6.0 (including)
Linux Conectiva ecommerce (including) ecommerce (including)
Linux Conectiva graficas (including) graficas (including)

References