Bug#552518: libc6: ldd arbitrary code execution vulnerability

2009-10-27 Thread Aurelien Jarno
On Mon, Oct 26, 2009 at 05:03:56PM -0400, Michael Gilbert wrote: > package: eglibc > version: 2.10.1-2 > severity: important > tags: security > > it has been disclosed that it is possible to execute arbitrary code via > ldd. this is a pretty obscure attack vector since it requires the user > to r

Bug#552518: libc6: ldd arbitrary code execution vulnerability

2009-10-26 Thread Michael Gilbert
package: eglibc version: 2.10.1-2 severity: important tags: security it has been disclosed that it is possible to execute arbitrary code via ldd. this is a pretty obscure attack vector since it requires the user to run ldd on an untrusted executable. while unlikely (since users using ldd should