Plesk

CVE-2023-4911: Vulnerability in glibc’s ld.so

Situation

CVE-2023-4911 was discovered in glibc's ld.so.

Impact

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable (CVE-2023-4911). This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.

Call to action

The vulnerability affects the system library. Plesk doesn't ship its own glibc. So, it is fixed by the system package's update.
 
OS vendor's advisories should be followed to update the vulnerable library.

These Linux distributions have already published fixes:

Exit mobile version