When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.
turbolinux
Vendor: turbolinux
Security Vulnerability Index
Page 1 / 2Buffer overflow in fdmount on Linux systems allows local users in the "floppy" group to execute arbitrary commands via a long mountpoint parameter.
Buffer overflow in the dump utility in the Linux ext2fs backup package allows local users to gain privileges via a long command line argument.
Buffer overflow in the man program in Linux allows local users to gain privileges via the MANPAGER environmental variable.
Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) attack.
Buffer overflow in uum program for Canna input system allows local users to gain root privileges.
Buffer overflow in canuum program for Canna input system allows local users to gain root privileges.