CVE-2001-0169: Low severity Mandrakesoft Mandrake Linux vulnerability
When using the LDPRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-0169?
CVE-2001-0169 is classified as a high-severity local security vulnerability.
How do I fix CVE-2001-0169?
To fix CVE-2001-0169, update glibc to a version that properly checks SUID/SGID permissions for preloaded libraries.
Which systems are affected by CVE-2001-0169?
CVE-2001-0169 affects multiple Linux distributions, including Mandrake Linux, Red Hat Linux, and Trustix Secure Linux in specific versions.
Can CVE-2001-0169 be exploited remotely?
CVE-2001-0169 cannot be exploited remotely; it requires local access to the affected system.
What can attackers achieve by exploiting CVE-2001-0169?
Exploitation of CVE-2001-0169 allows attackers to overwrite arbitrary files on a vulnerable system.