« List of all CVEs

CVE-2000-0824

Published: 1/22/2001 Last updated: 8/8/2024 Reserved: 10/15/2000

The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arbitrary commands in setuid programs by specifying their own duplicate environmental variables such as LD_PRELOAD or LD_LIBRARY_PATH.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (1)

gettext-stub

Products affected (1)

Product Vendor Version
n/a n/a < 3e7c7df6991ac349f2fa8540047757df666e610f

References (30)