CVE-2017-1000366: Debian Linux
High severity, CVSS 7.8. EPSS: 2.7% chance of exploitation in the next 30 days.
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these issues are not directly exploitable, as such they have not been given a CVE. This affects glibc 2.25 and earlier.
Affected products
- Debian Debian Linux: version 8.0 only; version 9.0 only
- GNU Glibc: up to and including 2.25
- McAfee Web Gateway: up to and including 7.6.2.14; from 7.7.0.0, up to and including 7.7.2.2
- Novell Suse Linux Enterprise Desktop: version 12.0 only
- Novell Suse Linux Enterprise Point Of Sale: version 11.0 only
- Novell Suse Linux Enterprise Server: version 11.0 only
- Openstack Cloud Magnum Orchestration: version 7 only
- Opensuse Leap: version 42.2 only
- Red Hat Enterprise Linux: version 5 only; version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server: version 6.0 only; version 6.6 only; version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 5.9 only; version 6.2 only; version 6.4 only; version 6.5 only; version 6.6 only; version 7.2 only; …
- Red Hat Enterprise Linux Server Eus: version 6.2 only; version 6.5 only; version 6.7 only; version 7.2 only; version 7.3 only; version 7.4 only; …
- Red Hat Enterprise Linux Server Long Life: version 5.9 only
- Red Hat Enterprise Linux Server Tus: version 6.5 only; version 6.6 only; version 7.2 only; version 7.3 only; version 7.6 only
- Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
- Suse Linux Enterprise For SAP: version 12 only
- Suse Linux Enterprise Server: version 10 only; version 11 only; version 12 only
- Suse Linux Enterprise Server For Raspberry Pi: version 12 only
- Suse Linux Enterprise Software Development Kit: version 11.0 only; version 12.0 only
Published 2017-06-19. Last modified 2026-06-17.