CNCVE编号:CNCVE-20010170 CVE编号:CVE-2001-0170 安全级别:中 漏洞中文描述: 当执行setuid/setgid程序时,glibc 2.1.9x 及其早期版本不能正确地清除 RESOLV_HOST_CONF, HOSTALIASES,或 RES_OPTIONS环境变量, 这允许本地用户阅读任意文件。 漏洞英文描述: glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files. 漏洞参考: BUGTRAQ:20010110 Glibc Local Root Exploit BUGTRAQ:20010110