CVE-2017-1000408
HIGHglibc <2.1.1 - Memory Corruption
Title source: llmDescription
A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Qualys Corporation · textlocallinux
https://www.exploit-db.com/exploits/43331
References (6)
Scores
CVSS v3
7.8
EPSS
0.0076
EPSS Percentile
73.0%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-772
Status
published
Affected Products (1)
gnu/glibc
Timeline
Published
Feb 01, 2018
Tracked Since
Feb 18, 2026