Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-5119

Опубликовано: 14 июл. 2014
Источник: redhat
CVSS2: 6.9
EPSS Средний

Описание

Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment variable and gconv transliteration modules.

An off-by-one heap-based buffer overflow flaw was found in glibc's internal __gconv_translit_find() function. An attacker able to make an application call the iconv_open() function with a specially crafted argument could possibly use this flaw to execute arbitrary code with the privileges of that application.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux Extended Update Support 5.6glibcAffected
Red Hat Enterprise Linux 5glibcFixedRHSA-2014:111029.08.2014
Red Hat Enterprise Linux 5.6 Long LifeglibcFixedRHSA-2014:111802.09.2014
Red Hat Enterprise Linux 5.9 Extended Update SupportglibcFixedRHSA-2014:111802.09.2014
Red Hat Enterprise Linux 6glibcFixedRHSA-2014:111029.08.2014
Red Hat Enterprise Linux 6.2 Advanced Update SupportglibcFixedRHSA-2014:111802.09.2014
Red Hat Enterprise Linux 6.4 Extended Update SupportglibcFixedRHSA-2014:111802.09.2014
Red Hat Enterprise Linux 7glibcFixedRHSA-2014:111029.08.2014

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-193->CWE-626->CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1119128glibc: off-by-one error leading to a heap-based buffer overflow flaw in __gconv_translit_find()

EPSS

Процентиль: 94%
0.1342
Средний

6.9 Medium

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment variable and gconv transliteration modules.

nvd
около 11 лет назад

Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment variable and gconv transliteration modules.

debian
около 11 лет назад

Off-by-one error in the __gconv_translit_find function in gconv_trans. ...

github
больше 3 лет назад

Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment variable and gconv transliteration modules.

fstec
около 11 лет назад

Уязвимость операционной системы Red Hat Enterprise Linux, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 94%
0.1342
Средний

6.9 Medium

CVSS2