Executive Summary

Informations
NameCVE-2010-3856First vendor Publication2011-01-07
VendorCveLast vendor Modification2011-02-12

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score7.2Attack RangeLocal
Cvss Impact Score10Attack ComplexityLow
Cvss Expoit Score3.9AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment variable to reference dynamic shared objects (DSOs) as audit objects, which allows local users to gain privileges by leveraging an unsafe DSO located in a trusted library directory, as demonstrated by libpcprofile.so.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3856

CWE : Common Weakness Enumeration

idName
CWE-264Permissions, Privileges, and Access Controls

CPE : Common Platform Enumeration

TypeDescriptionCount
Application55

ExploitDB Exploits

idDescription
2011-11-10glibc LD_AUDIT arbitrary DSO load Privilege Escalation
2010-10-22GNU C library dynamic linker LD_AUDIT arbitrary DSO load Vulnerability

Open Source Vulnerability Database (OSVDB)

idDescription
68920GNU C Library Dynamic Linker LD_AUDIT non-setuid Library Loading Issue

Internal Sources (Detail)

SourceUrl
BIDhttp://www.securityfocus.com/bid/44347
BUGTRAQhttp://www.securityfocus.com/archive/1/archive/1/515545/100/0/threaded
CONFIRMhttp://support.avaya.com/css/P8/documents/100121017
http://www.vmware.com/security/advisories/VMSA-2011-0001.html
https://bugzilla.redhat.com/show_bug.cgi?id=645672
DEBIANhttp://www.debian.org/security/2010/dsa-2122
FULLDISChttp://seclists.org/fulldisclosure/2010/Oct/344
GENTOOhttp://security.gentoo.org/glsa/glsa-201011-01.xml
MANDRIVAhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:212
MLISThttp://sourceware.org/ml/libc-hacker/2010-10/msg00010.html
REDHAThttp://www.redhat.com/support/errata/RHSA-2010-0872.html
https://rhn.redhat.com/errata/RHSA-2010-0793.html
SECUNIAhttp://secunia.com/advisories/42787
UBUNTUhttp://www.ubuntu.com/usn/USN-1009-1
VUPENhttp://www.vupen.com/english/advisories/2011/0025

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
DateInformations
2013-05-10 23:35:03
  • Multiple Updates
2013-05-01 17:22:39
  • Multiple Updates
2013-05-01 13:28:07
  • Multiple Updates
2013-05-01 09:22:48
  • Multiple Updates
2013-05-01 05:38:32
  • Multiple Updates