PT-2014-1817 · Gnu+5 · Glibc+5

Publicado

2014-09-02

·

Atualizado

2024-06-15

·

CVE-2014-6040

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions glibc versions prior to 2.20 glibc-devel-2.12 version glibc-debuginfo-2.12 version glibc-debuginfo-common-2.12 version glibc-2.12 version glibc-common-2.12 version glibc-static-2.12 version glibc-utils-2.12 version glibc-headers-2.12 version
Description The issue is related to multiple vulnerabilities in the glibc package, which can lead to disruption of confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be done remotely. The vulnerabilities allow context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via a multibyte character value of "0xffff" to the iconv function when converting certain encoded data to UTF-8.
Recommendations For glibc versions prior to 2.20, update to version 2.20 or later. For glibc-devel-2.12, glibc-debuginfo-2.12, glibc-debuginfo-common-2.12, glibc-2.12, glibc-common-2.12, glibc-static-2.12, glibc-utils-2.12, and glibc-headers-2.12, consider disabling the iconv function or restricting access to it until a patch is available. As a temporary workaround, consider avoiding the use of the iconv function with certain encoded data until the issue is resolved.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-2084
BDU:2015-06193
BDU:2015-06194
BDU:2015-06195
BDU:2015-06196
BDU:2015-06197
BDU:2015-06198
BDU:2015-06199
BDU:2015-06200
BDU:2015-09219
BDU:2015-09220
BDU:2015-09221
BDU:2015-09222
BDU:2015-09223
BDU:2015-09224
BDU:2015-09225
BDU:2015-09226
CESA-2015_0016
CESA-2015_0327
CVE-2014-6040
DLA-97-1
DSA-3142-1
MGASA-2014-0376
OPENSUSE-SU-2014_1115-1
OPENSUSE-SU-2024:10154-1
RHSA-2015:0016
RHSA-2015:0327
RHSA-2015_0016
RHSA-2015_0327
SUSE-RU-2015:0794-1
SUSE-SU-2015:0253-1
SUSE-SU-2015:0439-1
SUSE-SU-2015:0551-1
USN-2432-1

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Glibc