REDHAT-BUG-2367468: Medium severity GNU C Library vulnerability
Untrusted LDLIBRARYPATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2367468?
The vulnerability REDHAT-BUG-2367468 is classified as a high severity issue due to its potential for enabling untrusted library loading in setuid binaries.
How do I fix REDHAT-BUG-2367468?
To address REDHAT-BUG-2367468, update the GNU C Library to a version later than 2.38.
Which versions of the GNU C Library are affected by REDHAT-BUG-2367468?
REDHAT-BUG-2367468 affects GNU C Library versions 2.27 to 2.38.
What are the potential impacts of REDHAT-BUG-2367468?
Exploitation of REDHAT-BUG-2367468 may allow attackers to execute arbitrary code with elevated privileges via untrusted library loading.
Is REDHAT-BUG-2367468 a local or remote vulnerability?
REDHAT-BUG-2367468 is primarily considered a local vulnerability, as it requires an attacker to have local access to the system.