glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.
References
Configurations
Information
Published : 2000-12-18 21:00
Updated : 2017-10-09 18:29
NVD link : CVE-2000-0959
Mitre link : CVE-2000-0959
JSON object : View
CWE
Products Affected
gnu
- glibc