Executive Summary

Informations
NameCVE-2010-3847First vendor Publication2011-01-07
VendorCveLast vendor Modification2011-03-07

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:M/Au:N/C:C/I:C/A:C)
Cvss Base Score6.9Attack RangeLocal
Cvss Impact Score10Attack ComplexityMedium
Cvss Expoit Score3.4AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via a crafted dynamic shared object (DSO) located in an arbitrary directory.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3847

CWE : Common Weakness Enumeration

idName
CWE-59Improper Link Resolution Before File Access ('Link Following')

CPE : Common Platform Enumeration

TypeDescriptionCount
Application55

ExploitDB Exploits

idDescription
2010-10-22GNU C library dynamic linker LD_AUDIT arbitrary DSO load Vulnerability
2010-10-18GNU C library dynamic linker $ORIGIN expansion Vulnerability

Open Source Vulnerability Database (OSVDB)

idDescription
68721GNU C Library Dynamic Linker $ORIGIN Substitution Expansion Weakness Local Pr...

Internal Sources (Detail)

SourceUrl
BIDhttp://www.securityfocus.com/bid/44154
BUGTRAQhttp://www.securityfocus.com/archive/1/archive/1/515545/100/0/threaded
CERT-VNhttp://www.kb.cert.org/vuls/id/537223
CONFIRMhttp://support.avaya.com/css/P8/documents/100120941
http://www.vmware.com/security/advisories/VMSA-2011-0001.html
https://bugzilla.redhat.com/show_bug.cgi?id=643306
DEBIANhttp://www.debian.org/security/2010/dsa-2122
FULLDISChttp://seclists.org/fulldisclosure/2010/Oct/257
http://seclists.org/fulldisclosure/2010/Oct/292
http://seclists.org/fulldisclosure/2010/Oct/294
GENTOOhttp://security.gentoo.org/glsa/glsa-201011-01.xml
MANDRIVAhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:207
MLISThttp://sourceware.org/ml/libc-hacker/2010-10/msg00007.html
REDHAThttp://www.redhat.com/support/errata/RHSA-2010-0872.html
https://rhn.redhat.com/errata/RHSA-2010-0787.html
SECUNIAhttp://secunia.com/advisories/42787
UBUNTUhttp://www.ubuntu.com/usn/USN-1009-1
VUPENhttp://www.vupen.com/english/advisories/2011/0025

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
DateInformations
2013-05-10 23:34:56
  • Multiple Updates
2013-05-01 17:22:39
  • Multiple Updates
2013-05-01 13:28:07
  • Multiple Updates
2013-05-01 09:22:47
  • Multiple Updates
2013-05-01 05:38:32
  • Multiple Updates