CVE-2001-0170 describes a vulnerability in glibc versions 2.1.9x and earlier, affecting distributions like Conectiva, Debian, Immunix, and Red Hat. This flaw allows local users to read arbitrary files due to improper clearing of specific environmental variables (RESOLV_HOST_CONF, HOSTALIASES, RES_OPTIONS) during the execution of setuid/setgid programs. Rated with a low CVSS score of 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N), it requires local access and has a low impact, primarily leading to information disclosure. While not listed on the KEV catalog and showing no active exploitation or community discussion, exploit code exists on ExploitDB, indicating its potential for abuse by an attacker with local access.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0_betaCPE matchmatch criteria | cpe:2.3:a:immunix:immunix:7.0_beta:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:o:conectiva:linux:4.0:*:*:*:*:*:*:* | ||
4.0esCPE matchmatch criteria | cpe:2.3:o:conectiva:linux:4.0es:*:*:*:*:*:*:* | ||
4.1CPE matchmatch criteria | cpe:2.3:o:conectiva:linux:4.1:*:*:*:*:*:*:* | ||
4.2CPE matchmatch criteria | cpe:2.3:o:conectiva:linux:4.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.