6.9
CVSSv2

CVE-2017-1000409

Published: 01/02/2018 Updated: 04/04/2019
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
CVSS v3 Base Score: 7 | Impact Score: 5.9 | Exploitability Score: 1
VMScore: 695
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu glibc 2.5

Vendor Advisories

Debian Bug report logs - #884132 glibc: CVE-2017-1000408 Package: src:glibc; Maintainer for src:glibc is GNU Libc Maintainers <debian-glibc@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 11 Dec 2017 19:39:01 UTC Severity: important Tags: security, upstream Found in version glibc/ ...
Debian Bug report logs - #884133 glibc: CVE-2017-1000409 Package: src:glibc; Maintainer for src:glibc is GNU Libc Maintainers <debian-glibc@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 11 Dec 2017 19:39:04 UTC Severity: important Tags: security, upstream Found in version glibc/ ...
Several security issues were fixed in the GNU C library ...
A buffer overflow in glibc 25 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environment variable Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366 ...

Exploits

Qualys Security Advisory Buffer overflow in glibc's ldso ======================================================================== Contents ======================================================================== Summary Memory Leak Buffer Overflow Exploitation Acknowledgments ================================================================== ...
Qualys has discovered a memory leak and a buffer overflow in the dynamic loader (ldso) of the GNU C Library (glibc) ...