← Back

CVE-2001-0169

nvd nist
Published: Mar 26, 2001Modified: Apr 16, 2026

JSON object

Loading...
2.1
Vector
AV:L/AC:L/Au:N/C:N/I:P/A:N
Exploitability: 3.9 / Impact: 2.9
Source: NVD

Description

When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.

Affected (19)

Show all products
2 products
Mandrake Linux
Mandrake Linux Corporate Server
1 product
Linux
1 product
Secure Linux
1 product
Turbolinux
Configuration A
19 vulnerable
Vulnerable SoftwareAffected Versions
Mandrakesoft
Version 6.0
Version 6.1
Version 7.0
Version 7.1
Version 7.2
Version 1.0.1
Redhat
Version 6.0
Version 6.0
Version 6.0
Version 6.1
Version 6.1
Version 6.1
Version 6.2
Version 6.2
Version 6.2
Trustix
Version 1.1
Version 1.2
Turbolinux
Up to 6.0.5
Version 6.1

References (18)

Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.