Vulnerabilities > CVE-2001-0170

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files.

Exploit-Db

  • descriptionglibc-2.2 and openssh-2.3.0p1 exploits glibc >= 2.1.9x. CVE-2001-0170. Local exploit for linux platform
    idEDB-ID:258
    last seen2016-01-31
    modified2001-01-25
    published2001-01-25
    reporterkrochos
    sourcehttps://www.exploit-db.com/download/258/
    titleglibc-2.2 and openssh-2.3.0p1 Exploits glibc <= 2.1.9x
  • descriptionResolv+ (RESOLV_HOST_CONF) Linux Library Local Exploit. CVE-2001-0170. Local exploit for linux platform
    idEDB-ID:317
    last seen2016-01-31
    modified1996-01-01
    published1996-01-01
    reporterJared Mauch
    sourcehttps://www.exploit-db.com/download/317/
    titleResolv+ RESOLV_HOST_CONF - Linux Library Local Exploit

Redhat

advisories
rhsa
idRHSA-2001:001