Rule Name:Linux glibc LD_DEBUG Debugging Information Leakage Vulnerability
Severity:high
CVE ID:
Descripiton:
The LD_DEBUG debug information in Linux glibc is the dynamic linking debug log output by the glibc dynamic linker during program startup. Attackers can inject the LD_DEBUG parameter into user-controllable locations, causing the glibc dynamic linker to output sensitive debug information when a child process starts, thereby exposing critical intelligence such as the system version and file system structure. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021. Other reference:None