CVE-2004-1453: Low severity GNU glibc vulnerability
Published Dec 31, 2004
·Updated
GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does not restrict the use of LDDEBUG for a setuid program, which allows local users to gain sensitive information, such as the list of symbols used by the program.
Affected Software
25 affected components
GNU glibc=2.2.2
GNU glibc=2.1.2
GNU glibc=2.0.5
GNU glibc=2.2.5
GNU glibc=2.0.6
GNU glibc=2.1.1
GNU glibc=2.0.3
GNU glibc=2.3.1
GNU glibc=2.3
GNU glibc=2.0
GNU glibc=2.1.1.6
GNU glibc=2.1
GNU glibc=2.3.4
GNU glibc=2.1.9
GNU glibc=2.3.3
GNU glibc=2.0.1
GNU glibc=2.0.4
GNU glibc=2.0.2
GNU glibc=2.2.1
GNU glibc=2.3.2
GNU glibc=2.1.3.10
GNU glibc=2.2.3
GNU glibc=2.2.4
GNU glibc=2.1.3
GNU glibc=2.2
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Feb 13, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1453?
CVE-2004-1453 is considered a moderate severity vulnerability due to the potential exposure of sensitive information.
2
How do I fix CVE-2004-1453?
To fix CVE-2004-1453, update GNU libc (glibc) to version 2.3.4 or later.
3
What versions of glibc are affected by CVE-2004-1453?
CVE-2004-1453 affects glibc versions prior to 2.3.4, including 2.3.3, 2.3.2, and earlier releases.
4
What type of information can be leaked by CVE-2004-1453?
CVE-2004-1453 can leak sensitive information such as the list of symbols used by a setuid program.
5
Who is impacted by CVE-2004-1453?
Local users on systems running vulnerable versions of glibc are impacted by CVE-2004-1453.