Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).
References
Configurations
No configuration.
History
20 May 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
19 May 2025, 13:35
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
17 May 2025, 08:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
17 May 2025, 03:16
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
17 May 2025, 01:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
16 May 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-16 20:15
Updated : 2025-05-20 14:15
NVD link : CVE-2025-4802
Mitre link : CVE-2025-4802
CVE.ORG link : CVE-2025-4802
JSON object : View
Products Affected
No product.
CWE
CWE-426
Untrusted Search Path