vendor:
glibc
by:
Charles Stevenson (csteven@newhope.terraplex.com)
7.5
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: glibc
Affected Version From: glibc-2.1.9x
Affected Version To: glibc-2.2
Patch Exists: NO
Related CWE:
CPE: a:glibc:glibc:2.2
Platforms Tested: Debian 2.3, Redhat 7.0
2001
SSH Exploit for glibc-2.2 and openssh-2.3.0p1
This exploit takes advantage of a glibc bug to escalate privileges and read the /etc/shadow file. It is specifically designed for glibc versions 2.1.9x and above.
Mitigation:
Upgrade glibc to a version that is not vulnerable to this exploit. Remove setuid permissions from vulnerable binaries.