Security Advisory

CVE-2001-0170

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2001-05-07 04:00:00
Last updated 2024-08-08 04:14:06
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files.