CVE-2004-1453

GNU glibc <2.3.4-2.3.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does not restrict the use of LD_DEBUG for a setuid program, which allows local users to gain sensitive information, such as the list of symbols used by the program.

References (8)

Core 8
Core References
Issue Tracking x_refsource_misc
http://bugs.gentoo.org/show_bug.cgi?id=59526
Third Party Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200408-16.xml
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-261.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-256.html
Patch third-party-advisory x_refsource_secunia
http://secunia.com/advisories/12306
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10762
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17006
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10963

Scores

EPSS 0.0008
EPSS Percentile 23.0%

Details

Status published
Products (25)
gnu/glibc 2.0
gnu/glibc 2.0.1
gnu/glibc 2.0.2
gnu/glibc 2.0.3
gnu/glibc 2.0.4
gnu/glibc 2.0.5
gnu/glibc 2.0.6
gnu/glibc 2.1
gnu/glibc 2.1.1
gnu/glibc 2.1.1.6
... and 15 more
Published Dec 31, 2004
Tracked Since Feb 18, 2026