CVE-2019-1010023: High severity GNU glibc vulnerability
Published Jul 15, 2019
·Updated
DISPUTED GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat."
Affected Software
2 affected components
GNU glibc
debian/glibc<=2.31-13+deb11u11, <=2.31-13+deb11u13, <=2.36-9+deb12u13, <=2.36-9+deb12u7, <=2.41-12+deb13u1, <=2.42-13
Event History
Jul 15, 2019
CVE Published
via MITRE·03:09 AM
Data Sourced
via MITRE·03:09 AM
DescriptionWeakness
Disputed
04:15 AM
Feb 20, 2026
Data Sourced
via Debian·09:50 PM
DescriptionAffected Software
Data Sourced
via Ubuntu·09:51 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·09:51 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this GNU Libc vulnerability?
The vulnerability ID of this GNU Libc vulnerability is CVE-2019-1010023.
2
What is the severity of CVE-2019-1010023?
The severity of CVE-2019-1010023 is high with a severity value of 8.8.
3
What is the component affected by CVE-2019-1010023?
The component affected by CVE-2019-1010023 is libld.
4
What is the impact of CVE-2019-1010023?
The impact of CVE-2019-1010023 is that in the worst case scenario, an attacker may elevate privileges.
5
What is the remedy for CVE-2019-1010023?
There is currently no known remedy for CVE-2019-1010023.