CVE-2019-1010023 describes a vulnerability in GNU Libc (glibc) where a malicious ELF file can remap a currently loaded library, potentially leading to privilege escalation. The attack requires an attacker to send two ELF files to a victim and convince them to run 'ldd' on them, which then executes code. This vulnerability carries a high CVSS score of 8.8, indicating significant potential impact (confidentiality, integrity, availability) with low attack complexity, but relies on user interaction. Despite its severity, upstream developers consider it a non-security bug with no real threat, and there is no known active exploitation, publicly available exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:gnu:glibc:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.