9.3

CVE-2017-16997

elf/dl-load.c in the GNU C Library (aka glibc or libc6) 2.19 through 2.26 mishandles RPATH and RUNPATH containing $ORIGIN for a privileged (setuid or AT_SECURE) program, which allows local users to gain privileges via a Trojan horse library in the current working directory, related to the fillin_rpath and decompose_rpath functions. This is associated with misinterpretion of an empty RPATH/RUNPATH token as the "./" directory. NOTE: this configuration of RPATH/RUNPATH for a privileged program is apparently very uncommon; most likely, no such program is shipped with any common Linux distribution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gnu ≫ Glibc Version 2.19
Gnu ≫ Glibc Version 2.20
Gnu ≫ Glibc Version 2.21
Gnu ≫ Glibc Version 2.22
Gnu ≫ Glibc Version 2.23
Gnu ≫ Glibc Version 2.25
Gnu ≫ Glibc Version 2.26
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.7% 0.84
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-426 Untrusted Search Path

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

http://www.securityfocus.com/bid/102228
Third Party Advisory
VDB Entry
https://access.redhat.com/errata/RHBA-2019:0327
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:3092
Third Party Advisory
https://bugs.debian.org/884615
Patch
Third Party Advisory
Mailing List
Issue Tracking
https://sourceware.org/bugzilla/show_bug.cgi?id=22625
Patch
Third Party Advisory
Issue Tracking
https://sourceware.org/ml/libc-alpha/2017-12/msg00528.html
Patch
Third Party Advisory
Issue Tracking