GNU GLibC LD_DEBUG Local Information Disclosure Vulnerability
BID:10963
Info
GNU GLibC LD_DEBUG Local Information Disclosure Vulnerability
| Bugtraq ID: | 10963 |
| Class: | Design Error |
| CVE: |
CVE-2004-1453 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 17 2004 12:00AM |
| Updated: | Aug 05 2010 07:45PM |
| Credit: | Discovery of this vulnerability is credited to Silvio Cesare. |
| Vulnerable: |
SGI ProPack 3.0 SGI Advanced Linux Environment 3.0 GNU glibc 2.3.4 GNU glibc 2.3.3 GNU glibc 2.3.2 GNU glibc 2.3.1 GNU glibc 2.3 GNU glibc 2.2.5 GNU glibc 2.2.4 GNU glibc 2.2.3 GNU glibc 2.2.2 GNU glibc 2.2.1 GNU glibc 2.2 GNU glibc 2.1.9 and Greater GNU glibc 2.1.9 GNU glibc 2.1.3 -10 GNU glibc 2.1.3 GNU glibc 2.1.2 GNU glibc 2.1.1 -6 GNU glibc 2.1.1 GNU glibc 2.1 GNU glibc 2.0.6 GNU glibc 2.0.5 GNU glibc 2.0.4 GNU glibc 2.0.3 GNU glibc 2.0.2 GNU glibc 2.0.1 GNU glibc 2.0 Gentoo Linux 1.4 _rc3 Gentoo Linux 1.4 _rc2 Gentoo Linux 1.4 _rc1 Gentoo Linux 1.4 Gentoo Linux 1.2 Gentoo Linux 1.1 a Gentoo Linux 0.7 Gentoo Linux 0.5 Avaya Integrated Management 2.1 Avaya Integrated Management Avaya CVLAN |
| Not Vulnerable: | |
Discussion
GNU GLibC LD_DEBUG Local Information Disclosure Vulnerability
A local vulnerability is reported to exist in glibc, it is reported that LD_DEBUG is allowed on setuid binaries even though this should not be allowed. A local attacker may debug a setuid binary and may disclose sensitive information.
Information harvested in this manner may be employed to aid in further attacks that are launched against a vulnerable host.
A local vulnerability is reported to exist in glibc, it is reported that LD_DEBUG is allowed on setuid binaries even though this should not be allowed. A local attacker may debug a setuid binary and may disclose sensitive information.
Information harvested in this manner may be employed to aid in further attacks that are launched against a vulnerable host.
Exploit / POC
GNU GLibC LD_DEBUG Local Information Disclosure Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
GNU GLibC LD_DEBUG Local Information Disclosure Vulnerability
Solution:
Gentoo has released an advisory (GLSA 200408-16) and updated eBuilds to address this issue. Gentoo users are advised to execute the following commands as a superuser in order to apply the fixes and bring their system up to date.
emerge sync
emerge -pv your_version
emerge your_version
Where 'your_version' is the version of glibc that is installed on the Gentoo Linux host.
SGI has released advisory 20050503-01-U, along with SGI Advanced Linux Environment 3 Security Update #38 to address this, and other issues. Please see the referenced advisory for further information.
Avaya has relased advisory ASA-2005-155 to identify vulnerable Avaya products. Avaya recommends that customers should install vendor upgrades depending on the underlying operating systems running Avaya products.
Solution:
Gentoo has released an advisory (GLSA 200408-16) and updated eBuilds to address this issue. Gentoo users are advised to execute the following commands as a superuser in order to apply the fixes and bring their system up to date.
emerge sync
emerge -pv your_version
emerge your_version
Where 'your_version' is the version of glibc that is installed on the Gentoo Linux host.
SGI has released advisory 20050503-01-U, along with SGI Advanced Linux Environment 3 Security Update #38 to address this, and other issues. Please see the referenced advisory for further information.
Avaya has relased advisory ASA-2005-155 to identify vulnerable Avaya products. Avaya recommends that customers should install vendor upgrades depending on the underlying operating systems running Avaya products.
References
GNU GLibC LD_DEBUG Local Information Disclosure Vulnerability
References:
References: