CVE-2017-1000409: Buffer Overflow
A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LDLIBRARYPATH environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-1000409?
CVE-2017-1000409 is a buffer overflow vulnerability in glibc 2.5 that can be triggered through the LD_LIBRARY_PATH environment variable.
How can CVE-2017-1000409 be exploited?
The vulnerability can be exploited by a malformed LD_LIBRARY_PATH environment variable that leads to a buffer overflow, potentially allowing an attacker to execute arbitrary code.
Is glibc version 2.23-0ubuntu10 affected by CVE-2017-1000409?
Yes, glibc version 2.23-0ubuntu10 is affected by CVE-2017-1000409.
How can I fix CVE-2017-1000409 on Ubuntu?
To fix CVE-2017-1000409 on Ubuntu, update glibc to version 2.23-0ubuntu10 or higher.
Where can I find more information about CVE-2017-1000409?
More information about CVE-2017-1000409 can be found at the following references: [Reference 1](http://seclists.org/oss-sec/2017/q4/385), [Reference 2](https://security.netapp.com/advisory/ntap-20190404-0003/), [Reference 3](https://www.exploit-db.com/exploits/43331/).