CVE-2009-5064

UnknownEPSS 0.54%

Last modified

CVE-2009-5064 is a vulnerability of currently unknown severity. ldd in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows local users to gain privileges via a Trojan horse executable file linked with a modified loader that omits certain LD_TRACE_LOADED_OBJECTS checks. NOTE: the GNU C Library vendor states "This is just nonsense. EPSS estimates a 0.54% chance of exploitation in the next 30 days.

Description

ldd in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows local users to gain privileges via a Trojan horse executable file linked with a modified loader that omits certain LD_TRACE_LOADED_OBJECTS checks. NOTE: the GNU C Library vendor states "This is just nonsense. There are a gazillion other ways to introduce code if people are downloading arbitrary binaries and install them in appropriate directories or set LD_LIBRARY_PATH etc.

Metrics

EPSS Probability
0.54%

41.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
GnuGlibc<= 2.1.3
GnuGlibc1.00
GnuGlibc1.01
GnuGlibc1.02
GnuGlibc1.03
GnuGlibc1.04
GnuGlibc1.05
GnuGlibc1.06
GnuGlibc1.07
GnuGlibc1.08
GnuGlibc1.09
GnuGlibc1.09.1
GnuGlibc2.0
GnuGlibc2.0.1
GnuGlibc2.0.2
GnuGlibc2.0.3
GnuGlibc2.0.4
GnuGlibc2.0.5
GnuGlibc2.0.6
GnuGlibc2.1
GnuGlibc2.1.1
GnuGlibc2.1.1.6
GnuGlibc2.1.2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2009-5064?
ldd in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows local users to gain privileges via a Trojan horse executable file linked with a modified loader that omits certain LD_TRACE_LOADED_OBJECTS checks. NOTE: the GNU C Library vendor states "This is just nonsense. There are a gazillion other ways to introduce code if people are downloading arbitrary binaries and install them in appropriate directories or set LD_LIBRARY_PATH etc.
How severe is CVE-2009-5064?
Severity scoring for CVE-2009-5064 is pending analysis. The EPSS model estimates a 0.54% probability of exploitation in the next 30 days.
How do I fix CVE-2009-5064?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2009-5064?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST