Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Saeed Abbasi

Researcher fromQualys
#35367of 56,330
7.8Total CVSS
Vulnerabilities · 1
PT-2023-5614
7.8
2023-10-03
Gnu · Glibc · CVE-2023-4911
**Name of the Vulnerable Software and Affected Versions** GNU C Library versions 2.34 and later **Description** A buffer overflow exists in the dynamic loader `ld.so` of the GNU C Library (glibc) when processing the `GLIBC TUNABLES` environment variable. A local attacker can exploit this by using maliciously crafted `GLIBC TUNABLES` variables when launching binaries with SUID permissions to execute arbitrary code with elevated privileges, potentially gaining root access. The issue was introduced in April 2021 with the release of glibc version 2.34. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.