CVE-2009-4146: High severity freebsd kernel vulnerability
The rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1, 7.2, and 8.0 does not clear the LDPRELOAD environment variable, which allows local users to gain privileges by executing a setuid or setguid program with a modified LDPRELOAD variable containing an untrusted search path that points to a Trojan horse library, a different vector than CVE-2009-4147.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4146?
CVE-2009-4146 is classified as a high severity vulnerability due to its potential to allow local users to gain elevated privileges.
How do I fix CVE-2009-4146?
To fix CVE-2009-4146, you should upgrade to a patched version of FreeBSD that addresses this vulnerability.
Who is affected by CVE-2009-4146?
CVE-2009-4146 affects users of FreeBSD versions 7.1, 7.2, and 8.0.
What type of vulnerability is CVE-2009-4146?
CVE-2009-4146 is a local privilege escalation vulnerability in the Run-Time Link-Editor.
What can exploit CVE-2009-4146?
CVE-2009-4146 can be exploited by executing a setuid or setguid program with a modified LD_PRELOAD variable.