It was found that a buffer overflow can be triggered through the LD_LIBRARY_PATH environment variable.
Acknowledgments: Name: Qualys Research Labs
Public via: http://seclists.org/oss-sec/2017/q4/385
Created glibc tracking bugs for this issue: Affects: fedora-all [bug 1524867]
Statement: This issue did not affect the versions of glibc as shipped with Red Hat Enterprise Linux 5, 6 and 7 after CVE-2017-1000366 fix: https://access.redhat.com/security/cve/cve-2017-1000366
Upstream bug: https://sourceware.org/bugzilla/show_bug.cgi?id=22607 Upstream commit: https://sourceware.org/git/gitweb.cgi?p=glibc.git;a=commitdiff;h=3ff3dfa5af313a6ea33f3393916f30eece4f0171