Menu

#99 [Patch] CVE-2010-3384: insecure library loading

closed
1
2012-07-03
2010-10-17
Rudy Godoy
No

Please, find attached a patch for the CVE vulnerability issue encountered by the Debian team.

Description:
The vulnerability is introduced by an insecure change to LD_LIBRARY_PATH, and environment variable used by ld.so(8) to look for libraries on a directory other than the standard paths.

Discussion

  • Rudy Godoy

    Rudy Godoy - 2010-10-17

    CVE-2010-3384

     
  • Bernhard Wymann

    Bernhard Wymann - 2011-12-29

    will be in 1.3.2