CVE Vulnerabilities

CVE-2010-3856

Published: Jan 07, 2011 | Modified: Jul 20, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
7.2 IMPORTANT
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
HIGH

ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment variable to reference dynamic shared objects (DSOs) as audit objects, which allows local users to gain privileges by leveraging an unsafe DSO located in a trusted library directory, as demonstrated by libpcprofile.so.

Affected Software

Name Vendor Start Version End Version
Glibc Gnu * 2.11.2 (including)
Glibc Gnu 1.00 (including) 1.00 (including)
Glibc Gnu 1.01 (including) 1.01 (including)
Glibc Gnu 1.02 (including) 1.02 (including)
Glibc Gnu 1.03 (including) 1.03 (including)
Glibc Gnu 1.04 (including) 1.04 (including)
Glibc Gnu 1.05 (including) 1.05 (including)
Glibc Gnu 1.06 (including) 1.06 (including)
Glibc Gnu 1.07 (including) 1.07 (including)
Glibc Gnu 1.08 (including) 1.08 (including)
Glibc Gnu 1.09 (including) 1.09 (including)
Glibc Gnu 1.09.1 (including) 1.09.1 (including)
Glibc Gnu 2.0 (including) 2.0 (including)
Glibc Gnu 2.0.1 (including) 2.0.1 (including)
Glibc Gnu 2.0.2 (including) 2.0.2 (including)
Glibc Gnu 2.0.3 (including) 2.0.3 (including)
Glibc Gnu 2.0.4 (including) 2.0.4 (including)
Glibc Gnu 2.0.5 (including) 2.0.5 (including)
Glibc Gnu 2.0.6 (including) 2.0.6 (including)
Glibc Gnu 2.1 (including) 2.1 (including)
Glibc Gnu 2.1.1 (including) 2.1.1 (including)
Glibc Gnu 2.1.1.6 (including) 2.1.1.6 (including)
Glibc Gnu 2.1.2 (including) 2.1.2 (including)
Glibc Gnu 2.1.3 (including) 2.1.3 (including)
Glibc Gnu 2.1.3.10 (including) 2.1.3.10 (including)
Glibc Gnu 2.1.9 (including) 2.1.9 (including)
Glibc Gnu 2.2 (including) 2.2 (including)
Glibc Gnu 2.2.1 (including) 2.2.1 (including)
Glibc Gnu 2.2.2 (including) 2.2.2 (including)
Glibc Gnu 2.2.3 (including) 2.2.3 (including)
Glibc Gnu 2.2.4 (including) 2.2.4 (including)
Glibc Gnu 2.2.5 (including) 2.2.5 (including)
Glibc Gnu 2.3 (including) 2.3 (including)
Glibc Gnu 2.3.1 (including) 2.3.1 (including)
Glibc Gnu 2.3.2 (including) 2.3.2 (including)
Glibc Gnu 2.3.3 (including) 2.3.3 (including)
Glibc Gnu 2.3.4 (including) 2.3.4 (including)
Glibc Gnu 2.3.5 (including) 2.3.5 (including)
Glibc Gnu 2.3.6 (including) 2.3.6 (including)
Glibc Gnu 2.3.10 (including) 2.3.10 (including)
Glibc Gnu 2.4 (including) 2.4 (including)
Glibc Gnu 2.5 (including) 2.5 (including)
Glibc Gnu 2.5.1 (including) 2.5.1 (including)
Glibc Gnu 2.6 (including) 2.6 (including)
Glibc Gnu 2.6.1 (including) 2.6.1 (including)
Glibc Gnu 2.7 (including) 2.7 (including)
Glibc Gnu 2.8 (including) 2.8 (including)
Glibc Gnu 2.9 (including) 2.9 (including)
Glibc Gnu 2.10 (including) 2.10 (including)
Glibc Gnu 2.10.1 (including) 2.10.1 (including)
Glibc Gnu 2.10.2 (including) 2.10.2 (including)
Glibc Gnu 2.11 (including) 2.11 (including)
Glibc Gnu 2.11.1 (including) 2.11.1 (including)
Glibc Gnu 2.12.0 (including) 2.12.0 (including)
Glibc Gnu 2.12.1 (including) 2.12.1 (including)
Eglibc Ubuntu karmic *
Eglibc Ubuntu lucid *
Eglibc Ubuntu maverick *
Glibc Ubuntu hardy *
Glibc Ubuntu jaunty *
Red Hat Enterprise Linux 5 RedHat glibc-0:2.5-49.el5_5.7 *
Red Hat Enterprise Linux 6 RedHat glibc-0:2.12-1.7.el6_0.3 *

References