CVE-2017-16997 is a high-severity vulnerability in the GNU C Library (glibc) versions 2.19 through 2.26, affecting various Red Hat Enterprise Linux distributions. It allows local users to gain privileges by exploiting mishandling of RPATH and RUNPATH containing $ORIGIN in privileged programs, specifically when an empty RPATH/RUNPATH token is misinterpreted as the current directory. The vulnerability has a CVSS score of 7.8, indicating a high potential for impact on confidentiality, integrity, and availability, with a low attack complexity requiring user interaction. Despite its severity, there is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, suggesting it is not widely targeted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.19CPE matchmatch criteria | cpe:2.3:a:gnu:glibc:2.19:*:*:*:*:*:*:* | ||
2.20CPE matchmatch criteria | cpe:2.3:a:gnu:glibc:2.20:*:*:*:*:*:*:* | ||
2.21CPE matchmatch criteria | cpe:2.3:a:gnu:glibc:2.21:*:*:*:*:*:*:* | ||
2.22CPE matchmatch criteria | cpe:2.3:a:gnu:glibc:2.22:*:*:*:*:*:*:* | ||
2.23CPE matchmatch criteria | cpe:2.3:a:gnu:glibc:2.23:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.