GNU GLibC LD_DEBUG Local Information Disclosure Vulnerability

A local vulnerability is reported to exist in glibc, it is reported that LD_DEBUG is allowed on setuid binaries even though this should not be allowed. A local attacker may debug a setuid binary and may disclose sensitive information.

Information harvested in this manner may be employed to aid in further attacks that are launched against a vulnerable host.


 

Privacy Statement
Copyright 2010, SecurityFocus