CVE
- Id
- 2393
- CVE No.
- CVE-2000-0824
- Status
- Entry
- Description
- The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arbitrary commands in setuid programs by specifying their own duplicate environmental variables such as LD_PRELOAD or LD_LIBRARY_PATH.
- Phase
- Votes
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
8806 | 2393 | CVE-2000-0824 | BUGTRAQ:19990917 A few bugs... | View |
8807 | 2393 | CVE-2000-0824 | URL:http://marc.info/?l=bugtraq&m=93760201002154&w=2 | View |
8808 | 2393 | CVE-2000-0824 | BUGTRAQ:20000831 glibc unsetenv bug | View |
8809 | 2393 | CVE-2000-0824 | URL:http://www.securityfocus.com/archive/1/79537 | View |
8810 | 2393 | CVE-2000-0824 | CALDERA:CSSA-2000-028.0 | View |
8811 | 2393 | CVE-2000-0824 | URL:http://www.calderasystems.com/support/security/advisories/CSSA-2000-028.0.txt | View |
8812 | 2393 | CVE-2000-0824 | DEBIAN:20000902 glibc: local root exploit | View |
8813 | 2393 | CVE-2000-0824 | URL:http://www.debian.org/security/2000/20000902 | View |
8814 | 2393 | CVE-2000-0824 | MANDRAKE:MDKSA-2000:040 | View |
8815 | 2393 | CVE-2000-0824 | URL:http://www.linux-mandrake.com/en/updates/MDKSA-2000-040.php3 | View |
8816 | 2393 | CVE-2000-0824 | MANDRAKE:MDKSA-2000:045 | View |
8817 | 2393 | CVE-2000-0824 | URL:http://www.linux-mandrake.com/en/updates/MDKSA-2000-045.php3 | View |
8818 | 2393 | CVE-2000-0824 | REDHAT:RHSA-2000:057 | View |
8819 | 2393 | CVE-2000-0824 | URL:http://www.redhat.com/support/errata/RHSA-2000-057.html | View |
8820 | 2393 | CVE-2000-0824 | TURBO:TLSA2000020-1 | View |
8821 | 2393 | CVE-2000-0824 | URL:http://www.turbolinux.com/pipermail/tl-security-announce/2000-September/000020.html | View |
8822 | 2393 | CVE-2000-0824 | SUSE:20000924 glibc locale security problem | View |
8823 | 2393 | CVE-2000-0824 | URL:http://www.novell.com/linux/security/advisories/adv5_draht_glibc_txt.html | View |
8824 | 2393 | CVE-2000-0824 | BUGTRAQ:20000902 Conectiva Linux Security Announcement - glibc | View |
8825 | 2393 | CVE-2000-0824 | URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0436.html | View |
8826 | 2393 | CVE-2000-0824 | BUGTRAQ:20000905 Conectiva Linux Security Announcement - glibc | View |
8827 | 2393 | CVE-2000-0824 | URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0509.html | View |
8828 | 2393 | CVE-2000-0824 | BUGTRAQ:20000906 [slackware-security]: glibc 2.1.3 vulnerabilities patched | View |
8829 | 2393 | CVE-2000-0824 | URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0525.html | View |
8830 | 2393 | CVE-2000-0824 | BID:648 | View |
8831 | 2393 | CVE-2000-0824 | URL:http://www.securityfocus.com/bid/648 | View |
8832 | 2393 | CVE-2000-0824 | BID:1639 | View |
8833 | 2393 | CVE-2000-0824 | URL:http://www.securityfocus.com/bid/1639 | View |
8834 | 2393 | CVE-2000-0824 | XF:glibc-ld-unsetenv | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
64282 | JVNDB-2000-000062 | glib の unsetenv() 関数における任意のコマンドを実行される脆弱性 | glibc の unsetenv() 関数には、呼び出された際に重複している環境変数を除去しない脆弱性が存在します。 | CVE-2000-0824 | 2393 | 7.2 | http://jvndb.jvn.jp/ja/contents/2000/JVNDB-2000-000062.html | View |