VYPR
Unrated severityNVD Advisory· Published Nov 14, 2000· Updated Apr 16, 2026

CVE-2000-0824

CVE-2000-0824

Description

The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arbitrary commands in setuid programs by specifying their own duplicate environmental variables such as LD_PRELOAD or LD_LIBRARY_PATH.

Affected products

1
  • cpe:2.3:a:gnu:glibc:2.1.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

15

News mentions

0

No linked articles in our index yet.