PT-2014-9099 · Gnu+5 · Glibc+5

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2014-5119

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions glibc (affected versions not specified) glibc-devel (affected versions not specified) glibc-devel-32bit (affected versions not specified) glibc-devel-static (affected versions not specified) glibc-devel-static-32bit (affected versions not specified) glibc-extra (affected versions not specified) glibc-extra-debuginfo (affected versions not specified) glibc-html (affected versions not specified) glibc-i18ndata (affected versions not specified) glibc-info (affected versions not specified) glibc-locale (affected versions not specified) glibc-locale-32bit (affected versions not specified) glibc-locale-debuginfo (affected versions not specified) glibc-locale-debuginfo-32bit (affected versions not specified) glibc-profile (affected versions not specified) glibc-profile-32bit (affected versions not specified) glibc-utils (affected versions not specified) glibc-utils-32bit (affected versions not specified) glibc-utils-debuginfo (affected versions not specified) glibc-utils-debuginfo-32bit (affected versions not specified) glibc-utils-debugsource (affected versions not specified) nscd (affected versions not specified)
Description The issue is related to multiple vulnerabilities in the glibc package, which can lead to a disruption of confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be done remotely. The vulnerabilities are caused by an off-by-one error in the gconv translit find function in gconv trans.c in the GNU C Library (also known as glibc), allowing context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment variable and gconv transliteration modules.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-2084
BDU:2015-04284
BDU:2015-04285
BDU:2015-04286
BDU:2015-04287
BDU:2015-04288
BDU:2015-04289
BDU:2015-04290
BDU:2015-04291
BDU:2015-04292
BDU:2015-04293
BDU:2015-04294
BDU:2015-04295
BDU:2015-05856
BDU:2015-05857
BDU:2015-05858
BDU:2015-05859
BDU:2015-05860
BDU:2015-05861
BDU:2015-05862
BDU:2015-05863
BDU:2015-05864
BDU:2015-05865
BDU:2015-05866
BDU:2015-05867
BDU:2015-05868
BDU:2015-05869
BDU:2015-05870
BDU:2015-05871
BDU:2015-05872
BDU:2015-05873
BDU:2015-05874
BDU:2015-05875
BDU:2015-05876
BDU:2015-05877
BDU:2015-05878
BDU:2015-05879
BDU:2015-05880
BDU:2015-05881
BDU:2015-05882
BDU:2015-05883
BDU:2015-05884
BDU:2015-05885
BDU:2015-05886
BDU:2015-07218
BDU:2015-07220
BDU:2015-07222
BDU:2015-07224
BDU:2015-07226
BDU:2015-07228
BDU:2015-07231
CESA-2014_1110
CVE-2014-5119
DLA-43-1
DSA-3012-1
MGASA-2014-0376
OPENSUSE-SU-2014_1115-1
OPENSUSE-SU-2024:10154-1
RHSA-2014:1110
RHSA-2014:1118
RHSA-2014_1110
SUSE-RU-2015:0794-1
SUSE-SU-2014_1125-1
SUSE-SU-2015:0253-1
SUSE-SU-2015:0439-1
SUSE-SU-2015:0551-1
USN-2328-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Glibc