CVE-2001-0169

When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:mandrakesoft:mandrake_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:mandrakesoft:mandrake_linux:6.1:*:*:*:*:*:*:*
cpe:2.3:o:mandrakesoft:mandrake_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:mandrakesoft:mandrake_linux:7.1:*:*:*:*:*:*:*
cpe:2.3:o:mandrakesoft:mandrake_linux:7.2:*:*:*:*:*:*:*
cpe:2.3:o:mandrakesoft:mandrake_linux_corporate_server:1.0.1:*:*:*:*:*:*:*
cpe:2.3:o:redhat:linux:6.0:*:alpha:*:*:*:*:*
cpe:2.3:o:redhat:linux:6.0:*:i386:*:*:*:*:*
cpe:2.3:o:redhat:linux:6.0:*:sparc:*:*:*:*:*
cpe:2.3:o:redhat:linux:6.1:*:alpha:*:*:*:*:*
cpe:2.3:o:redhat:linux:6.1:*:i386:*:*:*:*:*
cpe:2.3:o:redhat:linux:6.1:*:sparc:*:*:*:*:*
cpe:2.3:o:redhat:linux:6.2:*:alpha:*:*:*:*:*
cpe:2.3:o:redhat:linux:6.2:*:i386:*:*:*:*:*
cpe:2.3:o:redhat:linux:6.2:*:sparc:*:*:*:*:*
cpe:2.3:o:trustix:secure_linux:1.1:*:*:*:*:*:*:*
cpe:2.3:o:trustix:secure_linux:1.2:*:*:*:*:*:*:*
cpe:2.3:o:turbolinux:turbolinux:*:*:*:*:*:*:*:*
cpe:2.3:o:turbolinux:turbolinux:6.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2001-03-26 05:00

Updated : 2023-12-10 10:17


NVD link : CVE-2001-0169

Mitre link : CVE-2001-0169

CVE.ORG link : CVE-2001-0169


JSON object : View

Products Affected

mandrakesoft

  • mandrake_linux
  • mandrake_linux_corporate_server

turbolinux

  • turbolinux

trustix

  • secure_linux

redhat

  • linux