[PATCH] CVE-2017-1000366: Ignore LD_LIBRARY_PATH for AT_SECURE=1 programs [BZ #21624]

Dmitry V. Levin ldv@altlinux.org
Mon Jun 19 16:23:00 GMT 2017


On Mon, Jun 19, 2017 at 05:38:32PM +0200, Florian Weimer wrote:
> LD_LIBRARY_PATH can only be used to reorder system search paths, which
> is not useful functionality.
> 
> This makes an exploitable unbounded alloca in _dl_init_paths unreachable
> for AT_SECURE=1 programs.
> 
> 2017-06-19  Florian Weimer  <fweimer@redhat.com>
> 
> 	[BZ #21624]
> 	CVE-2017-1000366
> 	* elf/rtld.c (process_envvars): Ignore LD_LIBRARY_PATH for
> 	__libc_enable_secure.

This is fine, please apply.


-- 
ldv
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 801 bytes
Desc: not available
URL: <http://sourceware.org/pipermail/libc-alpha/attachments/20170619/8c06adb0/attachment.sig>


More information about the Libc-alpha mailing list