Red Hat Bugzilla – Bug 1617412
CVE-2004-1453 security flaw
Last modified: 2018-08-16 14:02:15 EDT
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
GNU glibc 2.3.4 before 22.214.171.12440619, 2.3.3 before 126.96.36.19940420, and 2.3.2 before 2.3.2-r10 does not restrict the use of LD_DEBUG for a setuid program, which allows local users to gain sensitive information, such as the list of symbols used by the program.