glibc: LD_POINTER_GUARD in the environment is not sanitized
Published Jan 20, 2016
7.0
HIGHCVSS 3.0
EPSS 0.57%
Description
The process_envvars function in elf/rtld.c in the GNU C Library (aka glibc or libc6) before 2.23 allows local users to bypass a pointer-guarding protection mechanism via a zero value of the LD_POINTER_GUARD environment variable.
Affected products
No data.
No data.
Red Hat Enterprise Linux 7
glibc-0:2.17-196.el7
Fixed · RHSA-2017:1916
Red Hat Enterprise Linux 5
glibc
Will not fix
Red Hat Enterprise Linux 6
glibc
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | glibc-0:2.17-196.el7 | Fixed | RHSA-2017:1916 |
| Red Hat Enterprise Linux 5 | glibc | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | glibc | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
The glibc pointer guard is a post-exploitation mitigation mechanism. As such, it is only relevant if there are exploitable security vulnerabilities in the system. Therefore, applying available security updates to the system is a possible mitigation for this issue. In typical deployments, environment variables can only be set by users with shell access. Restricting shell access to trusted users is another possible mitigation.
References (19)
- http://hmarco.org/bugs/glibc_ptr_mangle_weakness.html x_refsource_MISCExploit
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177404.html vendor-advisoryx_refsource_FEDORA
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00036.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00037.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00038.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00039.html vendor-advisoryx_refsource_SUSE
- http://www.debian.org/security/2016/dsa-3480 vendor-advisoryx_refsource_DEBIAN
- http://www.openwall.com/lists/oss-security/2016/01/20/1 mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/81469 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1034811 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/USN-2985-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2985-2 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/errata/RHSA-2017:1916 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2015-8777 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1260581 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2015-8777
- https://security.gentoo.org/glsa/201702-11 vendor-advisoryx_refsource_GENTOO
- https://sourceware.org/bugzilla/show_bug.cgi?id=18928 x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2015-8777
Change history (0)
No recorded changes yet.