Memory corruption in GNU C Library (glibc) - CVE-2017-1000366

 

Memory corruption in GNU C Library (glibc) - CVE-2017-1000366

Published: June 20, 2017 / Updated: June 17, 2021


Vulnerability identifier: #VU7135
CSH Severity: Medium
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-1000366
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The vulnerability exists due to memory management errors in implementation of various functions under multiple operating systems. A local or remote attacker can trigger the affected application to process specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

GNU C Library (glibc)
Debian Linux
Gentoo Linux
Arch Linux
Amazon Linux AMI
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power
SUSE Linux
Ubuntu
Slackware Linux
Fedora
musl (Alpine package)
glibc
Red Hat Virtualization Host
Dynamic System Analysis (DSA) Preboot

How to mitigate CVE-2017-1000366

Install update from vendor's website.

musl (Alpine package) - update to 1.1.14-r15
Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
glibc - addressed in versions 2.23.1-12.fc24, 2.24-8.fc25, 2.25-6.fc26

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins