Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).
CVSS
No CVSS.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2025/05/16/7 | Mailing List |
http://www.openwall.com/lists/oss-security/2025/05/17/2 | Exploit Mailing List |
https://sourceware.org/bugzilla/show_bug.cgi?id=32976 | Issue Tracking |
https://sourceware.org/cgit/glibc/commit/?id=1e18586c5820e329f741d5c710275e165581380e | Patch |
Configurations
History
17 Jun 2025, 14:09
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:* | |
First Time |
Gnu glibc
Gnu |
|
References | () https://sourceware.org/bugzilla/show_bug.cgi?id=32976 - Issue Tracking | |
References | () http://www.openwall.com/lists/oss-security/2025/05/16/7 - Mailing List | |
References | () http://www.openwall.com/lists/oss-security/2025/05/17/2 - Exploit, Mailing List | |
References | () https://sourceware.org/cgit/glibc/commit/?id=1e18586c5820e329f741d5c710275e165581380e - Patch |
17 May 2025, 08:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
17 May 2025, 03:16
Type | Values Removed | Values Added |
---|---|---|
References |
|
16 May 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-16 20:15
Updated : 2025-06-17 14:09
NVD link : CVE-2025-4802
Mitre link : CVE-2025-4802
JSON object : View
Products Affected
gnu
- glibc
CWE
No CWE.