Oval Definition:oval:org.opensuse.security:def:20103856
Revision Date:2022-05-20Version:1
Title:CVE-2010-3856
Description:

ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment variable to reference dynamic shared objects (DSOs) as audit objects, which allows local users to gain privileges by leveraging an unsafe DSO located in a trusted library directory, as demonstrated by libpcprofile.so.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2010-3856
Mitre CVE-2010-3856
SUSE CVE-2010-3856
openSUSE-SU-2010:0912-1
openSUSE-SU-2010:0912-1
openSUSE-SU-2010:0913-1
openSUSE-SU-2010:0913-1
openSUSE-SU-2010:0914-1
openSUSE-SU-2010:0914-1
SUSE-SA:2010:052
SUSE-SA:2010:052
Platform(s):openSUSE 11.1
openSUSE 11.2
openSUSE 11.3
SUSE Linux Enterprise 11 Moblin 2.0
SUSE Linux Enterprise 11 Moblin 2.1
SUSE Linux Enterprise Desktop 10 SP3 for AMD64 and Intel EM64T
SUSE Linux Enterprise Desktop 10 SP3 for x86
SUSE Linux Enterprise Desktop 11 GA
SUSE Linux Enterprise Desktop 11 SP1
SUSE Linux Enterprise SDK 10 SP3
SUSE Linux Enterprise SDK 11 GA
SUSE Linux Enterprise Server 10 SP3
SUSE Linux Enterprise Server 11
SUSE Linux Enterprise Server 11 GA
SUSE Linux Enterprise Server 11 SP1
SUSE Linux Enterprise Server 11 SP1 for VMware
SUSE Linux Enterprise Server 11 SP1-TERADATA
SUSE Linux Enterprise Server for SAP 10 SP3
SUSE Linux Enterprise Server for SAP Applications 11
SUSE Linux Enterprise Server for SAP Applications 11 SP1-TERADATA
SUSE Linux Enterprise Software Development Kit 11 SP1
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Server 11 is installed
  • AND Package Information
  • glibc-2.9-13.11.1 is installed
  • OR glibc-32bit-2.9-13.11.1 is installed
  • OR glibc-devel-2.9-13.11.1 is installed
  • OR glibc-devel-32bit-2.9-13.11.1 is installed
  • OR glibc-html-2.9-13.11.1 is installed
  • OR glibc-i18ndata-2.9-13.11.1 is installed
  • OR glibc-info-2.9-13.11.1 is installed
  • OR glibc-locale-2.9-13.11.1 is installed
  • OR glibc-locale-32bit-2.9-13.11.1 is installed
  • OR glibc-locale-x86-2.9-13.11.1 is installed
  • OR glibc-profile-2.9-13.11.1 is installed
  • OR glibc-profile-32bit-2.9-13.11.1 is installed
  • OR glibc-profile-x86-2.9-13.11.1 is installed
  • OR glibc-x86-2.9-13.11.1 is installed
  • OR nscd-2.9-13.11.1 is installed
  • Definition Synopsis
  • Release Information
  • sles10-sp3 is installed
  • AND
  • glibc-32bit less than 2.4-31.77.76.1
  • OR glibc-64bit less than 2.4-31.77.76.1
  • OR glibc-devel-32bit less than 2.4-31.77.76.1
  • OR glibc-devel-64bit less than 2.4-31.77.76.1
  • OR glibc-devel less than 2.4-31.77.76.1
  • OR glibc-html less than 2.4-31.77.76.1
  • OR glibc-i18ndata less than 2.4-31.77.76.1
  • OR glibc-info less than 2.4-31.77.76.1
  • OR glibc-locale-32bit less than 2.4-31.77.76.1
  • OR glibc-locale-64bit less than 2.4-31.77.76.1
  • OR glibc-locale-x86 less than 2.4-31.77.76.1
  • OR glibc-locale less than 2.4-31.77.76.1
  • OR glibc-profile-32bit less than 2.4-31.77.76.1
  • OR glibc-profile-64bit less than 2.4-31.77.76.1
  • OR glibc-profile-x86 less than 2.4-31.77.76.1
  • OR glibc-profile less than 2.4-31.77.76.1
  • OR glibc-x86 less than 2.4-31.77.76.1
  • OR glibc less than 2.4-31.77.76.1
  • OR nscd less than 2.4-31.77.76.1
  • OR Package Information
  • sles10-sp3-sap is installed
  • AND
  • glibc-32bit less than 2.4-31.77.76.1
  • OR glibc-devel-32bit less than 2.4-31.77.76.1
  • OR glibc-devel less than 2.4-31.77.76.1
  • OR glibc-html less than 2.4-31.77.76.1
  • OR glibc-i18ndata less than 2.4-31.77.76.1
  • OR glibc-info less than 2.4-31.77.76.1
  • OR glibc-locale-32bit less than 2.4-31.77.76.1
  • OR glibc-locale less than 2.4-31.77.76.1
  • OR glibc-profile-32bit less than 2.4-31.77.76.1
  • OR glibc-profile less than 2.4-31.77.76.1
  • OR glibc less than 2.4-31.77.76.1
  • OR nscd less than 2.4-31.77.76.1
  • OR Package Information
  • sles10-sp3-sdk is installed
  • AND
  • glibc-dceext-32bit less than 2.4-31.77.76.1
  • OR glibc-dceext-64bit less than 2.4-31.77.76.1
  • OR glibc-dceext-x86 less than 2.4-31.77.76.1
  • OR glibc-dceext less than 2.4-31.77.76.1
  • OR glibc-html less than 2.4-31.77.76.1
  • OR glibc-profile-32bit less than 2.4-31.77.76.1
  • OR glibc-profile-64bit less than 2.4-31.77.76.1
  • OR glibc-profile-x86 less than 2.4-31.77.76.1
  • OR glibc-profile less than 2.4-31.77.76.1
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 11 is installed
  • AND
  • glibc-2.9-13.11 is installed
  • OR glibc-32bit-2.9-13.11 is installed
  • OR glibc-devel-2.9-13.11 is installed
  • OR glibc-devel-32bit-2.9-13.11 is installed
  • OR glibc-html-2.9-13.11 is installed
  • OR glibc-i18ndata-2.9-13.11 is installed
  • OR glibc-info-2.9-13.11 is installed
  • OR glibc-locale-2.9-13.11 is installed
  • OR glibc-locale-32bit-2.9-13.11 is installed
  • OR glibc-locale-x86-2.9-13.11 is installed
  • OR glibc-profile-2.9-13.11 is installed
  • OR glibc-profile-32bit-2.9-13.11 is installed
  • OR glibc-profile-x86-2.9-13.11 is installed
  • OR glibc-x86-2.9-13.11 is installed
  • OR nscd-2.9-13.11 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP1 is installed
  • AND
  • glibc-2.11.1-0.20 is installed
  • OR glibc-32bit-2.11.1-0.20 is installed
  • OR glibc-devel-2.11.1-0.20 is installed
  • OR glibc-devel-32bit-2.11.1-0.20 is installed
  • OR glibc-html-2.11.1-0.20 is installed
  • OR glibc-i18ndata-2.11.1-0.20 is installed
  • OR glibc-info-2.11.1-0.20 is installed
  • OR glibc-locale-2.11.1-0.20 is installed
  • OR glibc-locale-32bit-2.11.1-0.20 is installed
  • OR glibc-locale-x86-2.11.1-0.34 is installed
  • OR glibc-profile-2.11.1-0.20 is installed
  • OR glibc-profile-32bit-2.11.1-0.20 is installed
  • OR glibc-profile-x86-2.11.1-0.34 is installed
  • OR glibc-x86-2.11.1-0.34 is installed
  • OR nscd-2.11.1-0.20 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 11 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 11 is installed
  • AND
  • glibc-2.9-13.11 is installed
  • OR glibc-32bit-2.9-13.11 is installed
  • OR glibc-devel-2.9-13.11 is installed
  • OR glibc-devel-32bit-2.9-13.11 is installed
  • OR glibc-html-2.9-13.11 is installed
  • OR glibc-i18ndata-2.9-13.11 is installed
  • OR glibc-info-2.9-13.11 is installed
  • OR glibc-locale-2.9-13.11 is installed
  • OR glibc-locale-32bit-2.9-13.11 is installed
  • OR glibc-locale-x86-2.9-13.11 is installed
  • OR glibc-profile-2.9-13.11 is installed
  • OR glibc-profile-32bit-2.9-13.11 is installed
  • OR glibc-profile-x86-2.9-13.11 is installed
  • OR glibc-x86-2.9-13.11 is installed
  • OR nscd-2.9-13.11 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP1 is installed
  • AND
  • glibc-2.11.1-0.20 is installed
  • OR glibc-32bit-2.11.1-0.20 is installed
  • OR glibc-devel-2.11.1-0.20 is installed
  • OR glibc-devel-32bit-2.11.1-0.20 is installed
  • OR glibc-html-2.11.1-0.20 is installed
  • OR glibc-i18ndata-2.11.1-0.20 is installed
  • OR glibc-info-2.11.1-0.20 is installed
  • OR glibc-locale-2.11.1-0.20 is installed
  • OR glibc-locale-32bit-2.11.1-0.20 is installed
  • OR glibc-locale-x86-2.11.1-0.34 is installed
  • OR glibc-profile-2.11.1-0.20 is installed
  • OR glibc-profile-32bit-2.11.1-0.20 is installed
  • OR glibc-profile-x86-2.11.1-0.34 is installed
  • OR glibc-x86-2.11.1-0.34 is installed
  • OR nscd-2.11.1-0.20 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 11 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 11 is installed
  • AND
  • glibc-2.9-13.11 is installed
  • OR glibc-32bit-2.9-13.11 is installed
  • OR glibc-devel-2.9-13.11 is installed
  • OR glibc-devel-32bit-2.9-13.11 is installed
  • OR glibc-html-2.9-13.11 is installed
  • OR glibc-i18ndata-2.9-13.11 is installed
  • OR glibc-info-2.9-13.11 is installed
  • OR glibc-locale-2.9-13.11 is installed
  • OR glibc-locale-32bit-2.9-13.11 is installed
  • OR glibc-locale-x86-2.9-13.11 is installed
  • OR glibc-profile-2.9-13.11 is installed
  • OR glibc-profile-32bit-2.9-13.11 is installed
  • OR glibc-profile-x86-2.9-13.11 is installed
  • OR glibc-x86-2.9-13.11 is installed
  • OR nscd-2.9-13.11 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server for SAP Applications 11 SP1-TERADATA is installed
  • AND
  • glibc-2.11.1-0.20 is installed
  • OR glibc-32bit-2.11.1-0.20 is installed
  • OR glibc-devel-2.11.1-0.20 is installed
  • OR glibc-devel-32bit-2.11.1-0.20 is installed
  • OR glibc-html-2.11.1-0.20 is installed
  • OR glibc-i18ndata-2.11.1-0.20 is installed
  • OR glibc-info-2.11.1-0.20 is installed
  • OR glibc-locale-2.11.1-0.20 is installed
  • OR glibc-locale-32bit-2.11.1-0.20 is installed
  • OR glibc-profile-2.11.1-0.20 is installed
  • OR glibc-profile-32bit-2.11.1-0.20 is installed
  • OR libxcrypt-3.0.3-0.4 is installed
  • OR libxcrypt-32bit-3.0.3-0.4 is installed
  • OR nscd-2.11.1-0.20 is installed
  • OR pam-modules-11-1.18 is installed
  • OR pam-modules-32bit-11-1.18 is installed
  • OR pwdutils-3.2.8-0.4 is installed
  • OR pwdutils-plugin-audit-3.2.8-0.4 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP1-TERADATA is installed
  • AND
  • glibc-2.11.1-0.20 is installed
  • OR glibc-32bit-2.11.1-0.20 is installed
  • OR glibc-devel-2.11.1-0.20 is installed
  • OR glibc-devel-32bit-2.11.1-0.20 is installed
  • OR glibc-html-2.11.1-0.20 is installed
  • OR glibc-i18ndata-2.11.1-0.20 is installed
  • OR glibc-info-2.11.1-0.20 is installed
  • OR glibc-locale-2.11.1-0.20 is installed
  • OR glibc-locale-32bit-2.11.1-0.20 is installed
  • OR glibc-profile-2.11.1-0.20 is installed
  • OR glibc-profile-32bit-2.11.1-0.20 is installed
  • OR nscd-2.11.1-0.20 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP1 is installed
  • AND
  • glibc-2.11.1-0.20 is installed
  • OR glibc-32bit-2.11.1-0.58 is installed
  • OR glibc-devel-2.11.1-0.20 is installed
  • OR glibc-devel-32bit-2.11.1-0.58 is installed
  • OR glibc-html-2.11.1-0.20 is installed
  • OR glibc-i18ndata-2.11.1-0.20 is installed
  • OR glibc-info-2.11.1-0.20 is installed
  • OR glibc-locale-2.11.1-0.20 is installed
  • OR glibc-locale-32bit-2.11.1-0.58 is installed
  • OR glibc-locale-x86-2.11.1-0.38 is installed
  • OR glibc-profile-2.11.1-0.20 is installed
  • OR glibc-profile-32bit-2.11.1-0.58 is installed
  • OR glibc-profile-x86-2.11.1-0.38 is installed
  • OR glibc-x86-2.11.1-0.38 is installed
  • OR libxcrypt-3.0.3-0.4 is installed
  • OR libxcrypt-32bit-3.0.3-0.4 is installed
  • OR nscd-2.11.1-0.20 is installed
  • OR pam-modules-11-1.18 is installed
  • OR pam-modules-32bit-11-1.18 is installed
  • OR pwdutils-3.2.8-0.4 is installed
  • OR pwdutils-plugin-audit-3.2.8-0.4 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 11 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 11 is installed
  • AND
  • glibc-2.9-13.11.1 is installed
  • OR glibc-32bit-2.9-13.11.1 is installed
  • OR glibc-devel-2.9-13.11.1 is installed
  • OR glibc-devel-32bit-2.9-13.11.1 is installed
  • OR glibc-html-2.9-13.11.1 is installed
  • OR glibc-i18ndata-2.9-13.11.1 is installed
  • OR glibc-info-2.9-13.11.1 is installed
  • OR glibc-locale-2.9-13.11.1 is installed
  • OR glibc-locale-32bit-2.9-13.11.1 is installed
  • OR glibc-locale-x86-2.9-13.11.1 is installed
  • OR glibc-profile-2.9-13.11.1 is installed
  • OR glibc-profile-32bit-2.9-13.11.1 is installed
  • OR glibc-profile-x86-2.9-13.11.1 is installed
  • OR glibc-x86-2.9-13.11.1 is installed
  • OR nscd-2.9-13.11.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP1 is installed
  • AND
  • glibc-2.11.1-0.20.1 is installed
  • OR glibc-32bit-2.11.1-0.58.1 is installed
  • OR glibc-devel-2.11.1-0.20.1 is installed
  • OR glibc-devel-32bit-2.11.1-0.58.1 is installed
  • OR glibc-html-2.11.1-0.20.1 is installed
  • OR glibc-i18ndata-2.11.1-0.20.1 is installed
  • OR glibc-info-2.11.1-0.20.1 is installed
  • OR glibc-locale-2.11.1-0.20.1 is installed
  • OR glibc-locale-32bit-2.11.1-0.58.1 is installed
  • OR glibc-locale-x86-2.11.1-0.38.1 is installed
  • OR glibc-profile-2.11.1-0.20.1 is installed
  • OR glibc-profile-32bit-2.11.1-0.58.1 is installed
  • OR glibc-profile-x86-2.11.1-0.38.1 is installed
  • OR glibc-x86-2.11.1-0.38.1 is installed
  • OR libxcrypt-3.0.3-0.4.1 is installed
  • OR libxcrypt-32bit-3.0.3-0.4.1 is installed
  • OR nscd-2.11.1-0.20.1 is installed
  • OR pam-modules-11-1.18.1 is installed
  • OR pam-modules-32bit-11-1.18.1 is installed
  • OR pwdutils-3.2.8-0.4.1 is installed
  • OR pwdutils-plugin-audit-3.2.8-0.4.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP1-TERADATA is installed
  • AND
  • glibc-2.11.1-0.20.1 is installed
  • OR glibc-32bit-2.11.1-0.20.1 is installed
  • OR glibc-devel-2.11.1-0.20.1 is installed
  • OR glibc-devel-32bit-2.11.1-0.20.1 is installed
  • OR glibc-html-2.11.1-0.20.1 is installed
  • OR glibc-i18ndata-2.11.1-0.20.1 is installed
  • OR glibc-info-2.11.1-0.20.1 is installed
  • OR glibc-locale-2.11.1-0.20.1 is installed
  • OR glibc-locale-32bit-2.11.1-0.20.1 is installed
  • OR glibc-profile-2.11.1-0.20.1 is installed
  • OR glibc-profile-32bit-2.11.1-0.20.1 is installed
  • OR nscd-2.11.1-0.20.1 is installed
  • BACK