repostbot33@lemmy.worldB to netsec@lemmy.worldEnglish · 1 year agoCritical Provesc Zero Day in Confluenceconfluence.atlassian.comexternal-linkmessage-square1fedilinkarrow-up14arrow-down10cross-posted to: [email protected]
arrow-up14arrow-down1external-linkCritical Provesc Zero Day in Confluenceconfluence.atlassian.comrepostbot33@lemmy.worldB to netsec@lemmy.worldEnglish · 1 year agomessage-square1fedilinkcross-posted to: [email protected]
minus-squaresun_is_ralinkfedilinkEnglisharrow-up2·1 year ago a local attacker could exploit the shortcoming to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.