CVE-2001-0170: Low severity Conectiva Linux vulnerability
glibc 2.1.9x and earlier does not properly clear the RESOLVHOSTCONF, HOSTALIASES, or RESOPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-0170?
CVE-2001-0170 is classified as a high-severity vulnerability due to its potential to allow local users to access arbitrary files.
How do I fix CVE-2001-0170?
To fix CVE-2001-0170, upgrade to a version of glibc that properly clears the RESOLV_HOST_CONF, HOSTALIASES, and RES_OPTIONS environment variables.
What systems are affected by CVE-2001-0170?
CVE-2001-0170 affects various versions of Conectiva Linux, Debian GNU/Linux, and Red Hat Linux.
Can CVE-2001-0170 be exploited remotely?
CVE-2001-0170 cannot be exploited remotely, as it requires local access to the affected systems.
Is CVE-2001-0170 still a concern in modern systems?
CVE-2001-0170 is less of a concern in modern systems as most have moved to updated versions of glibc that mitigate this vulnerability.