In light of the recent #Qualys #advisory, I recommend reading this old #vulnerability report by @taviso that’s also cited by Qualys in their writeup.

The GNU C library dynamic linker will dlopen arbitrary DSOs during setuid loads.

https://seclists.org/fulldisclosure/2010/Oct/344

Full Disclosure: The GNU C library dynamic linker will dlopen arbitrary DSOs during setuid loads.