GNU glibc CVE-2017-1000366 Local Memory Corruption Vulnerability
by CIRT Team
Description: glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these issues are not directly exploitable, as such they have not been given a CVE. This affects glibc 2.25 and earlier.
Impact: An attacker could exploit this issue to execute arbitrary code in the context of the application. GNU glibc 2.25 and prior versions are vulnerable.
Mitigation: Updates are available. Please check specific vendor advisory for more information.
26 Oct 2023 - Security Advisories & Alerts