CVE-2019-1010023 PUBLISHED

GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.

EPSS 0.32% · 55.1th percentile

Risk Scores

EPSS Score
0.32%
55.1th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSglibc0, 2.23-0ubuntu11.3+esm9, 2.23-0ubuntu11.3+esm8
Ubuntu:Pro:20.04:LTSglibc2.31-0ubuntu9.18+esm1, 0, 2.30-0ubuntu2
Ubuntu:Pro:18.04:LTSglibc2.26-0ubuntu2.1, 2.27-0ubuntu2, 2.27-0ubuntu3
Ubuntu:Pro:14.04:LTSeglibc2.19-0ubuntu6.14, 2.19-0ubuntu6.13, 2.19-0ubuntu6.11

Timeline

References

Open in Interactive Console →