CVE-2017-16997
HIGH
7,8
Source: [email protected]
Attack Vector: local
Attack Complexity: low
Privileges Required: none
User Interaction: required
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
HIGH
9,3
Source: [email protected]
Access Vector: network
Access Complexity: medium
Authentication: none
Confidentiality: complete
Integrity: complete
Availability: complete
Description
AI Translation Available
elf/dl-load.c in the GNU C Library (aka glibc or libc6) 2.19 through 2.26 mishandles RPATH and RUNPATH containing $ORIGIN for a privileged (setuid or AT_SECURE) program, which allows local users to gain privileges via a Trojan horse library in the current working directory, related to the fillin_rpath and decompose_rpath functions. This is associated with misinterpretion of an empty RPATH/RUNPATH token as the './' directory. NOTE: this configuration of RPATH/RUNPATH for a privileged program is apparently very uncommon; most likely, no such program is shipped with any common Linux distribution.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0113
Percentile
0,8th
Updated
EPSS Score Trend (Last 90 Days)
426
Untrusted Search Path
StableCommon Consequences
Security Scopes Affected:
Integrity
Confidentiality
Availability
Access Control
Potential Impacts:
Gain Privileges Or Assume Identity
Execute Unauthorized Code Or Commands
Dos: Crash, Exit, Or Restart
Read Files Or Directories
Applicable Platforms
All platforms may be affected
Application
Glibc by Gnu
CPE Identifier
View Detailed Analysis
cpe:2.3:a:gnu:glibc:2.19:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Glibc by Gnu
CPE Identifier
View Detailed Analysis
cpe:2.3:a:gnu:glibc:2.23:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Enterprise Linux Desktop by Redhat
CPE Identifier
View Detailed Analysis
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Glibc by Gnu
CPE Identifier
View Detailed Analysis
cpe:2.3:a:gnu:glibc:2.25:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Glibc by Gnu
CPE Identifier
View Detailed Analysis
cpe:2.3:a:gnu:glibc:2.21:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Enterprise Linux Server by Redhat
CPE Identifier
View Detailed Analysis
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Glibc by Gnu
CPE Identifier
View Detailed Analysis
cpe:2.3:a:gnu:glibc:2.26:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Enterprise Linux Workstation by Redhat
CPE Identifier
View Detailed Analysis
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Glibc by Gnu
CPE Identifier
View Detailed Analysis
cpe:2.3:a:gnu:glibc:2.22:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Glibc by Gnu
CPE Identifier
View Detailed Analysis
cpe:2.3:a:gnu:glibc:2.20:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://access.redhat.com/errata/RHBA-2019:0327
https://access.redhat.com/errata/RHSA-2018:3092
https://bugs.debian.org/884615
https://sourceware.org/bugzilla/show_bug.cgi?id=22625
https://sourceware.org/ml/libc-alpha/2017-12/msg00528.html
http://www.securityfocus.com/bid/102228
https://access.redhat.com/errata/RHBA-2019:0327
https://access.redhat.com/errata/RHSA-2018:3092
https://bugs.debian.org/884615
https://sourceware.org/bugzilla/show_bug.cgi?id=22625
https://sourceware.org/ml/libc-alpha/2017-12/msg00528.html
http://www.securityfocus.com/bid/102228