CVE Vulnerabilities

CVE-2001-0170

Published: Mar 26, 2001 | Modified: Oct 10, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files.

Affected Software

Name Vendor Start Version End Version
Immunix Immunix 7.0_beta 7.0_beta
Linux Conectiva 4.0 4.0
Linux Conectiva 4.0es 4.0es
Linux Conectiva 4.1 4.1
Linux Conectiva 4.2 4.2
Linux Conectiva 5.0 5.0
Linux Conectiva 5.1 5.1
Linux Conectiva 6.0 6.0
Linux Conectiva ecommerce ecommerce
Linux Conectiva graficas graficas

References