glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.
AV:L/AC:H/Au:N/C:N/I:P/A:N
This vulnerability has a 0.30% probability of being exploited in the next 30 days, ranking higher than 21% of all scored CVEs.