Package name
Advisory ID
Affected versions
6.1 i586 , 6.0 i586

Problem description

A bug was discovered in that could allow local users to obtain root privileges. The dynamic loader,, is responsible for making shared libraries available within a program at run-time. Normally, a user is allowed to load additional shared libraries when executing a program; they can be specified with environment variables such as LD_PRELOAD. Because this is not acceptable for applications that are setuid root, normally removes these environment variables for setuid root programs. The discovered bug causes these environment variables to not be removed under certain circumstances. While setuid programs themselves are not vulnerable, external programs they execute can be affected by this problem. A number of additional bugs have been found in the glibc locale and internationaliztion security checks. In internationalized programs, users are permitted to select a locale or choose message catalogues using environment variables such as LANG or LC_*. The content of these variables is then used as part of the pathname used to search message catalogues or locale files. Under normal circumstances, if these variables contained the "/" character, a program could load the internationalization files from arbitrary directories. This is not acceptable for setuid programs, which is the reason glibc does not allow certain settings of these variables if the program is setuid or setgid. However, some of these checks were done in inapporpriate places, contained bugs, or were missing entirely. It is highly probable that some of these bugs can be used for local root exploits. Update: Packages are now available for Linux-Mandrake 6.0 and 6.1.

Updated packages

6.1 i586

 05e57344e0141d4f5085f78155b58b66  6.1/RPMS/glibc-2.1.3-16mdk.i586.rpm
284ee4868af286469169a4a6605d3172  6.1/RPMS/glibc-devel-2.1.3-16mdk.i586.rpm
114c605878c338ed36aabe9b673cd4fd  6.1/RPMS/glibc-profile-2.1.3-16mdk.i586.rpm
1f263ca77795b93b54e0af5644149407  6.1/SRPMS/glibc-2.1.3-16mdk.src.rpm

6.0 i586

 05e57344e0141d4f5085f78155b58b66  6.0/RPMS/glibc-2.1.3-16mdk.i586.rpm
284ee4868af286469169a4a6605d3172  6.0/RPMS/glibc-devel-2.1.3-16mdk.i586.rpm
114c605878c338ed36aabe9b673cd4fd  6.0/RPMS/glibc-profile-2.1.3-16mdk.i586.rpm
1f263ca77795b93b54e0af5644149407  6.0/SRPMS/glibc-2.1.3-16mdk.src.rpm