ld.so in the GNU C Library (aka glibc or libc6) 2.13 and earlier expands the $ORIGIN dynamic string token when RPATH is composed entirely of this token, which might allow local users to gain privileges by creating a hard link in an arbitrary directory to a (1) setuid or (2) setgid program with this RPATH value, and then executing the program with a crafted value for the LD_PRELOAD environment variable, a different vulnerability than CVE-2010-3847 and CVE-2011-0536. NOTE: it is not expected that any standard operating-system distribution would ship an applicable setuid or setgid program.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2011-04-08T15:00:00

Updated: 2024-08-06T22:37:24.622Z

Reserved: 2011-04-08T00:00:00

Link: CVE-2011-1658

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2011-04-08T15:17:28.493

Modified: 2018-10-09T19:31:31.350

Link: CVE-2011-1658

cve-icon Redhat

Severity : Low

Publid Date: 2011-01-12T00:00:00Z

Links: CVE-2011-1658 - Bugzilla