glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.
References
Configurations
History
No history.
Information
Published : 2000-12-19 05:00
Updated : 2017-10-10 01:29
NVD link : CVE-2000-0959
Mitre link : CVE-2000-0959
CVE.ORG link : CVE-2000-0959
JSON object : View
Products Affected
gnu
- glibc
CWE