PT-2014-1817 · Gnu+5 · Glibc+5

Published

2014-09-02

·

Updated

2024-06-15

·

CVE-2014-6040

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions glibc versions prior to 2.20 glibc-devel-2.12 version glibc-debuginfo-2.12 version glibc-debuginfo-common-2.12 version glibc-2.12 version glibc-common-2.12 version glibc-static-2.12 version glibc-utils-2.12 version glibc-headers-2.12 version
Description The issue is related to multiple vulnerabilities in the glibc package, which can lead to disruption of confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be done remotely. The vulnerabilities allow context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via a multibyte character value of "0xffff" to the iconv function when converting certain encoded data to UTF-8.
Recommendations For glibc versions prior to 2.20, update to version 2.20 or later. For glibc-devel-2.12, glibc-debuginfo-2.12, glibc-debuginfo-common-2.12, glibc-2.12, glibc-common-2.12, glibc-static-2.12, glibc-utils-2.12, and glibc-headers-2.12, consider disabling the iconv function or restricting access to it until a patch is available. As a temporary workaround, consider avoiding the use of the iconv function with certain encoded data until the issue is resolved.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-2084
BDU:2015-06193
BDU:2015-06194
BDU:2015-06195
BDU:2015-06196
BDU:2015-06197
BDU:2015-06198
BDU:2015-06199
BDU:2015-06200
BDU:2015-09219
BDU:2015-09220
BDU:2015-09221
BDU:2015-09222
BDU:2015-09223
BDU:2015-09224
BDU:2015-09225
BDU:2015-09226
CESA-2015_0016
CESA-2015_0327
CVE-2014-6040
DLA-97-1
DSA-3142-1
MGASA-2014-0376
OPENSUSE-SU-2014_1115-1
OPENSUSE-SU-2024:10154-1
RHSA-2015:0016
RHSA-2015:0327
RHSA-2015_0016
RHSA-2015_0327
SUSE-RU-2015:0794-1
SUSE-SU-2015:0253-1
SUSE-SU-2015:0439-1
SUSE-SU-2015:0551-1
USN-2432-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Glibc