CVE Vulnerabilities

CVE-2009-5064

Published: Mar 30, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
3.7 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

ldd in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows local users to gain privileges via a Trojan horse executable file linked with a modified loader that omits certain LD_TRACE_LOADED_OBJECTS checks. NOTE: the GNU C Library vendor states This is just nonsense. There are a gazillion other ways to introduce code if people are downloading arbitrary binaries and install them in appropriate directories or set LD_LIBRARY_PATH etc.

Affected Software

NameVendorStart VersionEnd Version
GlibcGnu*2.1.3 (including)
GlibcGnu1.00 (including)1.00 (including)
GlibcGnu1.01 (including)1.01 (including)
GlibcGnu1.02 (including)1.02 (including)
GlibcGnu1.03 (including)1.03 (including)
GlibcGnu1.04 (including)1.04 (including)
GlibcGnu1.05 (including)1.05 (including)
GlibcGnu1.06 (including)1.06 (including)
GlibcGnu1.07 (including)1.07 (including)
GlibcGnu1.08 (including)1.08 (including)
GlibcGnu1.09 (including)1.09 (including)
GlibcGnu1.09.1 (including)1.09.1 (including)
GlibcGnu2.0 (including)2.0 (including)
GlibcGnu2.0.1 (including)2.0.1 (including)
GlibcGnu2.0.2 (including)2.0.2 (including)
GlibcGnu2.0.3 (including)2.0.3 (including)
GlibcGnu2.0.4 (including)2.0.4 (including)
GlibcGnu2.0.5 (including)2.0.5 (including)
GlibcGnu2.0.6 (including)2.0.6 (including)
GlibcGnu2.1 (including)2.1 (including)
GlibcGnu2.1.1 (including)2.1.1 (including)
GlibcGnu2.1.1.6 (including)2.1.1.6 (including)
GlibcGnu2.1.2 (including)2.1.2 (including)
Red Hat Enterprise Linux 4RedHatglibc-0:2.3.4-2.57*
Red Hat Enterprise Linux 5RedHatglibc-0:2.5-65.el5_7.3*
Red Hat Enterprise Linux 6RedHatglibc-0:2.12-1.47.el6*
EglibcUbuntukarmic*
GlibcUbuntudapper*
GlibcUbuntudevel*
GlibcUbuntuhardy*

References