CVE Vulnerabilities

CVE-2011-1095

Published: Apr 10, 2011 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.2 MEDIUM
AV:L/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
3.7 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW

locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not quote its output, which might allow local users to gain privileges via a crafted localization environment variable, in conjunction with a program that executes a script that uses the eval function.

Affected Software

Name Vendor Start Version End Version
Glibc Gnu * 2.12.2 (including)
Glibc Gnu 1.00 (including) 1.00 (including)
Glibc Gnu 1.01 (including) 1.01 (including)
Glibc Gnu 1.02 (including) 1.02 (including)
Glibc Gnu 1.03 (including) 1.03 (including)
Glibc Gnu 1.04 (including) 1.04 (including)
Glibc Gnu 1.05 (including) 1.05 (including)
Glibc Gnu 1.06 (including) 1.06 (including)
Glibc Gnu 1.07 (including) 1.07 (including)
Glibc Gnu 1.08 (including) 1.08 (including)
Glibc Gnu 1.09 (including) 1.09 (including)
Glibc Gnu 1.09.1 (including) 1.09.1 (including)
Glibc Gnu 2.0 (including) 2.0 (including)
Glibc Gnu 2.0.1 (including) 2.0.1 (including)
Glibc Gnu 2.0.2 (including) 2.0.2 (including)
Glibc Gnu 2.0.3 (including) 2.0.3 (including)
Glibc Gnu 2.0.4 (including) 2.0.4 (including)
Glibc Gnu 2.0.5 (including) 2.0.5 (including)
Glibc Gnu 2.0.6 (including) 2.0.6 (including)
Glibc Gnu 2.1 (including) 2.1 (including)
Glibc Gnu 2.1.1 (including) 2.1.1 (including)
Glibc Gnu 2.1.1.6 (including) 2.1.1.6 (including)
Glibc Gnu 2.1.2 (including) 2.1.2 (including)
Glibc Gnu 2.1.3 (including) 2.1.3 (including)
Glibc Gnu 2.1.3.10 (including) 2.1.3.10 (including)
Glibc Gnu 2.1.9 (including) 2.1.9 (including)
Glibc Gnu 2.2 (including) 2.2 (including)
Glibc Gnu 2.2.1 (including) 2.2.1 (including)
Glibc Gnu 2.2.2 (including) 2.2.2 (including)
Glibc Gnu 2.2.3 (including) 2.2.3 (including)
Glibc Gnu 2.2.4 (including) 2.2.4 (including)
Glibc Gnu 2.2.5 (including) 2.2.5 (including)
Glibc Gnu 2.3 (including) 2.3 (including)
Glibc Gnu 2.3.1 (including) 2.3.1 (including)
Glibc Gnu 2.3.2 (including) 2.3.2 (including)
Glibc Gnu 2.3.3 (including) 2.3.3 (including)
Glibc Gnu 2.3.4 (including) 2.3.4 (including)
Glibc Gnu 2.3.5 (including) 2.3.5 (including)
Glibc Gnu 2.3.6 (including) 2.3.6 (including)
Glibc Gnu 2.3.10 (including) 2.3.10 (including)
Glibc Gnu 2.4 (including) 2.4 (including)
Glibc Gnu 2.5 (including) 2.5 (including)
Glibc Gnu 2.5.1 (including) 2.5.1 (including)
Glibc Gnu 2.6 (including) 2.6 (including)
Glibc Gnu 2.6.1 (including) 2.6.1 (including)
Glibc Gnu 2.7 (including) 2.7 (including)
Glibc Gnu 2.8 (including) 2.8 (including)
Glibc Gnu 2.9 (including) 2.9 (including)
Glibc Gnu 2.10 (including) 2.10 (including)
Glibc Gnu 2.10.1 (including) 2.10.1 (including)
Glibc Gnu 2.10.2 (including) 2.10.2 (including)
Glibc Gnu 2.11 (including) 2.11 (including)
Glibc Gnu 2.11.1 (including) 2.11.1 (including)
Glibc Gnu 2.11.2 (including) 2.11.2 (including)
Glibc Gnu 2.11.3 (including) 2.11.3 (including)
Glibc Gnu 2.12.0 (including) 2.12.0 (including)
Glibc Gnu 2.12.1 (including) 2.12.1 (including)
Red Hat Enterprise Linux 4 RedHat glibc-0:2.3.4-2.57 *
Red Hat Enterprise Linux 5 RedHat glibc-0:2.5-58.el5_6.2 *
Red Hat Enterprise Linux 6 RedHat glibc-0:2.12-1.7.el6_0.5 *
Eglibc Ubuntu karmic *
Eglibc Ubuntu lucid *
Eglibc Ubuntu maverick *
Glibc Ubuntu dapper *
Glibc Ubuntu hardy *

References