TGViewer
OpenBSD OpenBSD @openbsd · 1.23K subscribers
Post #102 892
OpenBSD Local Privilege Escalation in OpenBSD's dynamic loader (CVE-2019-19726) We discovered a Local Privilege Escalation in OpenBSD's dynamic loader (ld.so): this vulnerability is exploitable in the default installation (via the set-user-ID executable chpass or…
This Metasploit module exploits a vulnerability in the OpenBSD ld.so dynamic loader (CVE-2019-19726). The _dl_getenv() function fails to reset the LD_LIBRARY_PATH environment variable when set with approximately ARG_MAX colons. This can be abused to load libutil.so from an untrusted path, using LD_LIBRARY_PATH in combination with the chpass set-uid executable, resulting in privileged code execution. This module has been tested successfully on OpenBSD 6.1 (amd64) and OpenBSD 6.6 (amd64).

https://packetstormsecurity.com/files/155764

#security
More from @openbsd
  1. Oct 22, 2025OpenBSD 7.8 released. #release
  2. Oct 22, 2025Channel photo updated
  3. Sep 14, 2025How to perform common FreeBSD tasks on OpenBSD. This post will serve as reminder for mysel…
  4. Sep 14, 2025Adventures in porting a Wayland Compositor to NetBSD and OpenBSD. #video #wayland
  5. Apr 28, 2025OpenBSD 7.7 released! #release
  6. Apr 28, 2025Channel photo updated
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →