High severity7.0NVD Advisory· Published Mar 1, 2017· Updated May 13, 2026
CVE-2016-10151
CVE-2016-10151
Description
The hesiod_init function in lib/hesiod.c in Hesiod 3.2.1 compares EUID with UID to determine whether to use configurations from environment variables, which allows local users to gain privileges via the (1) HESIOD_CONFIG or (2) HES_DOMAIN environment variable and leveraging certain SUID/SGUID binary.
Affected products
1- cpe:2.3:a:hesiod_project:hesiod:3.2.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.openwall.com/lists/oss-security/2017/01/21/1nvdPatchThird Party Advisory
- github.com/achernya/hesiod/pull/9nvdIssue TrackingPatchThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue Tracking
- www.securityfocus.com/bid/90952nvd
- security.gentoo.org/glsa/201805-01nvd
News mentions
0No linked articles in our index yet.