CVE-2017-1000366 is a critical vulnerability in glibc versions 2.25 and earlier, affecting numerous Linux distributions and products including Debian, Red Hat, and SUSE. It allows a local attacker to manipulate the heap and stack via specially crafted LD_LIBRARY_PATH values, potentially leading to arbitrary code execution. With a CVSS score of 7.8 (HIGH), this vulnerability has a low attack complexity and can result in high impacts to confidentiality, integrity, and availability. While not on the KEV catalog, exploit code is publicly available on ExploitDB, detailing local privilege escalation techniques. Despite the availability of exploits, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:5:*:server:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.