CVE-2011-0536 describes multiple untrusted search path vulnerabilities in specific modified versions of the GNU C Library (glibc), including those in Red Hat Enterprise Linux. This flaw allows local users to escalate privileges by crafting a dynamic shared object (DSO) in a subdirectory when executing setuid or setgid programs that improperly handle $ORIGIN in RPATH or RUNPATH. With a CVSS score of 6.9, this vulnerability is considered medium severity, requiring local access and medium attack complexity, but potentially leading to complete compromise of confidentiality, integrity, and availability. It specifically impacts glibc and Red Hat Enterprise Linux distributions. While there is no evidence of active exploitation (KEV: No), an exploit for a related issue (EDB-15274) exists, suggesting the feasibility of exploitation. Community discussion and media coverage are minimal, indicating low public awareness despite the potential for privilege escalation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.5-49.el5_5.6CPE matchmatch criteria | cpe:2.3:a:gnu:glibc:2.5-49.el5_5.6:*:*:*:*:*:*:* | ||
2.12-1.7.el6_0.3CPE matchmatch criteria | cpe:2.3:a:gnu:glibc:2.12-1.7.el6_0.3:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.