about summary refs log tree commit diff
path: root/wcsmbs/wcscspn.c
diff options
context:
space:
mode:
authorFlorian Weimer <fweimer@redhat.com>2017-06-19 18:34:53 +0200
committerFlorian Weimer <fweimer@redhat.com>2017-06-19 18:34:53 +0200
commitefa26d9c13a6fabd34a05139e1d8b2e441b2fae9 (patch)
treea049c779caac19dd8856fe5871c1d02d14587385 /wcsmbs/wcscspn.c
parent9f172a30acdd64e140bedd438458830fa8c27ad8 (diff)
downloadglibc-efa26d9c13a6fabd34a05139e1d8b2e441b2fae9.tar.gz
glibc-efa26d9c13a6fabd34a05139e1d8b2e441b2fae9.tar.xz
glibc-efa26d9c13a6fabd34a05139e1d8b2e441b2fae9.zip
CVE-2017-1000366: Ignore LD_LIBRARY_PATH for AT_SECURE=1 programs [BZ #21624]
LD_LIBRARY_PATH can only be used to reorder system search paths, which
is not useful functionality.

This makes an exploitable unbounded alloca in _dl_init_paths unreachable
for AT_SECURE=1 programs.

(cherry picked from commit f6110a8fee2ca36f8e2d2abecf3cba9fa7b8ea7d)
Diffstat (limited to 'wcsmbs/wcscspn.c')
0 files changed, 0 insertions, 0 deletions