Root access vulnerability in glibc library impacts many Linux distros

https://securityaffairs.com/158369/security/gnu-library-c-glibc-cve-2023-6246-flaw.html

23 points · 3 comments · view on lemmy.world

3 Comments

immibis@social.immibis.com · 4 pts · 2y (2 replies)

@BlanK0 @security the fix commit says the problem occurs when the program name is very long - so probably not very exploitable, as the program name is usually set in stone.

BlanK0@lemmy.ml · 3 pts · 2y

Thx for pointing that out 🤙

CameronDev@programming.dev · 2 pts · 2y

Symlink or copy/rename could trigger it, as long as there is a user writable area with execute perms? /home usually allows exec?

Also some of the exec* functions allow manipulating the argv[0], so possibly another vector there.