CVE Vulnerabilities

CVE-2010-3856

Published: Jan 07, 2011 | Modified: Jul 20, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment variable to reference dynamic shared objects (DSOs) as audit objects, which allows local users to gain privileges by leveraging an unsafe DSO located in a trusted library directory, as demonstrated by libpcprofile.so.

Affected Software

Name Vendor Start Version End Version
Glibc Gnu * 2.11.2 (including)
Glibc Gnu 1.00 (including) 1.00 (including)
Glibc Gnu 1.01 (including) 1.01 (including)
Glibc Gnu 1.02 (including) 1.02 (including)
Glibc Gnu 1.03 (including) 1.03 (including)
Glibc Gnu 1.04 (including) 1.04 (including)
Glibc Gnu 1.05 (including) 1.05 (including)
Glibc Gnu 1.06 (including) 1.06 (including)
Glibc Gnu 1.07 (including) 1.07 (including)
Glibc Gnu 1.08 (including) 1.08 (including)
Glibc Gnu 1.09 (including) 1.09 (including)
Glibc Gnu 1.09.1 (including) 1.09.1 (including)
Glibc Gnu 2.0 (including) 2.0 (including)
Glibc Gnu 2.0.1 (including) 2.0.1 (including)
Glibc Gnu 2.0.2 (including) 2.0.2 (including)
Glibc Gnu 2.0.3 (including) 2.0.3 (including)
Glibc Gnu 2.0.4 (including) 2.0.4 (including)
Glibc Gnu 2.0.5 (including) 2.0.5 (including)
Glibc Gnu 2.0.6 (including) 2.0.6 (including)
Glibc Gnu 2.1 (including) 2.1 (including)
Glibc Gnu 2.1.1 (including) 2.1.1 (including)
Glibc Gnu 2.1.1.6 (including) 2.1.1.6 (including)
Glibc Gnu 2.1.2 (including) 2.1.2 (including)
Glibc Gnu 2.1.3 (including) 2.1.3 (including)
Glibc Gnu 2.1.3.10 (including) 2.1.3.10 (including)
Glibc Gnu 2.1.9 (including) 2.1.9 (including)
Glibc Gnu 2.2 (including) 2.2 (including)
Glibc Gnu 2.2.1 (including) 2.2.1 (including)
Glibc Gnu 2.2.2 (including) 2.2.2 (including)
Glibc Gnu 2.2.3 (including) 2.2.3 (including)
Glibc Gnu 2.2.4 (including) 2.2.4 (including)
Glibc Gnu 2.2.5 (including) 2.2.5 (including)
Glibc Gnu 2.3 (including) 2.3 (including)
Glibc Gnu 2.3.1 (including) 2.3.1 (including)
Glibc Gnu 2.3.2 (including) 2.3.2 (including)
Glibc Gnu 2.3.3 (including) 2.3.3 (including)
Glibc Gnu 2.3.4 (including) 2.3.4 (including)
Glibc Gnu 2.3.5 (including) 2.3.5 (including)
Glibc Gnu 2.3.6 (including) 2.3.6 (including)
Glibc Gnu 2.3.10 (including) 2.3.10 (including)
Glibc Gnu 2.4 (including) 2.4 (including)
Glibc Gnu 2.5 (including) 2.5 (including)
Glibc Gnu 2.5.1 (including) 2.5.1 (including)
Glibc Gnu 2.6 (including) 2.6 (including)
Glibc Gnu 2.6.1 (including) 2.6.1 (including)
Glibc Gnu 2.7 (including) 2.7 (including)
Glibc Gnu 2.8 (including) 2.8 (including)
Glibc Gnu 2.9 (including) 2.9 (including)
Glibc Gnu 2.10 (including) 2.10 (including)
Glibc Gnu 2.10.1 (including) 2.10.1 (including)
Glibc Gnu 2.10.2 (including) 2.10.2 (including)
Glibc Gnu 2.11 (including) 2.11 (including)
Glibc Gnu 2.11.1 (including) 2.11.1 (including)
Glibc Gnu 2.12.0 (including) 2.12.0 (including)
Glibc Gnu 2.12.1 (including) 2.12.1 (including)

References