Errata overview
Errata ID 333
Date 2018-04-18
Source package glibc
Fixed in version 2.19-18+deb8u10
Description
This update addresses the following issue:
* glibc contains a vulnerability that allows specially crafted
  LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias,
  potentially resulting in arbitrary code execution. Please note that
  additional hardening changes have been made to glibc to prevent
  manipulation of stack and heap memory but these issues are not directly
  exploitable, as such they have not been given a CVE. (CVE-2017-1000366)
Additional notes
CVE ID CVE-2017-1000366
UCS Bug number #44860