REDHAT-BUG-1260581: Low severity gnu c library (glibc) vulnerability
A weakness in the dynamic loader has been found, making glibc of versions prior 2.22.90 affected. LDPOINTERGUARD in the environment is not sanitizaed allowing attacker to easily bypass the pointer guarding protection on set-user-ID and set-group-ID programs.
Reproducing steps available at:
http://hmarco.org/bugs/glibcptrmangleweakness.html
CVE request:
http://seclists.org/oss-sec/2015/q3/504
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1260581?
The severity of REDHAT-BUG-1260581 is considered high due to its potential exploitation by attackers.
How do I fix REDHAT-BUG-1260581?
To fix REDHAT-BUG-1260581, upgrade your glibc to version 2.22.90 or later.
What versions of glibc are affected by REDHAT-BUG-1260581?
REDHAT-BUG-1260581 affects glibc versions prior to 2.22.90.
Who discovered REDHAT-BUG-1260581?
REDHAT-BUG-1260581 was discovered internally and documented by security researchers.
What type of vulnerability is REDHAT-BUG-1260581?
REDHAT-BUG-1260581 is a weakness in the dynamic loader that can lead to bypassing pointer protection mechanisms.