the buffer overflow (CVE-2017-1000409) first appeared in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environment variable. http://nvd.nist.gov/vuln/detail/CVE-2017-1000409