Bug 146403 - Information leak with LD_DEBUG
Information leak with LD_DEBUG
Product: Red Hat Enterprise Linux 2.1
Classification: Red Hat
Component: glibc (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Jakub Jelinek
Brian Brock
: Security
Depends On:
  Show dependency treegraph
Reported: 2005-01-27 16:48 EST by Leonard den Ottolander
Modified: 2016-11-24 09:48 EST (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2005-01-27 17:04:13 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Leonard den Ottolander 2005-01-27 16:48:22 EST
Silvio Cesare discovered a potential information leak in glibc. It
allows LD_DEBUG on SUID binaries where it should not be allowed. This
has various security implications, which may be used to gain
confidentional information.

P.S. Also applies to 2.1 DE, ES and WS.
Comment 1 Jakub Jelinek 2005-01-27 16:57:45 EST
2.1 doesn't have PIEs nor randomization, nor prelinking.  LD_DEBUG doesn't reveal
you something you can't find out otherwise.

Note You need to log in before you can comment on or make changes to this bug.