Input validation error in GNU C Library (glibc) - CVE-2014-5119
Published: August 29, 2014 / Updated: August 10, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment variable and gconv transliteration modules.
Affected software
Amazon Linux AMI
Gentoo Linux
SUSE Linux
Slackware Linux
glibc-solibs
glibc-profile
glibc-i18n
glibc
sys-libs/glibc
ProtecTIER Enterprise Edition (PID 5639-PTA) - TS7650G
ProtecTIER Entry Edition (PID 5639-PTC) - TS7610 / TS7620
ProtecTIER Appliance Edition (PID 5639-PTB) - TS7650AP1
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1
TMS RAMSAN 710 and 810 Machine Type 9834 -AS1 and -AE1
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2
How to mitigate CVE-2014-5119
glibc-solibs - update to 2.17
glibc-profile - update to 2.17
glibc-i18n - update to 2.17
glibc - update to 2.17
sys-libs/glibc - update to 2.21-r2
ProtecTIER Enterprise Edition (PID 5639-PTA) - TS7650G - addressed in versions 3.1.17, 3.3, 3.3.5.1, 3.3.6
ProtecTIER Entry Edition (PID 5639-PTC) - TS7610 / TS7620 - addressed in versions 3.1.17, 3.3, 3.3.5.1, 3.3.6
ProtecTIER Appliance Edition (PID 5639-PTB) - TS7650AP1 - addressed in versions 3.1.17, 3.3, 3.3.5.1, 3.3.6
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1 - update to 5.6.2
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1 - update to 5.6.2
TMS RAMSAN 710 and 810 Machine Type 9834 -AS1 and -AE1 - update to 6.3.2
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2 - update to 6.3.2
External References
- http://googleprojectzero.blogspot.com/2014/08/the-poisoned-nul-byte-2014-edition.html
- http://linux.oracle.com/errata/ELSA-2015-0092.html
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00017.html
- http://rhn.redhat.com/errata/RHSA-2014-1118.html
- http://seclists.org/fulldisclosure/2014/Aug/69
- http://secunia.com/advisories/60345
- http://secunia.com/advisories/60358
- http://secunia.com/advisories/60441
- http://secunia.com/advisories/61074
- http://secunia.com/advisories/61093
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-5119
- http://www.debian.org/security/2014/dsa-3012
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:175
- http://www.openwall.com/lists/oss-security/2014/07/14/1
- http://www.openwall.com/lists/oss-security/2014/08/13/5
- http://www.securityfocus.com/bid/68983
- http://www.securityfocus.com/bid/69738
- http://www-01.ibm.com/support/docview.wss?uid=swg21685604
- https://code.google.com/p/google-security-research/issues/detail?id=96
- https://rhn.redhat.com/errata/RHSA-2014-1110.html
- https://security.gentoo.org/glsa/201602-02
- https://sourceware.org/bugzilla/show_bug.cgi?id=17187
Related Security Bulletins
- Multiple vulnerabilities in Glibc
- SUSE Linux update for glibc
- SUSE Linux update for glibc
- Amazon Linux AMI update for glibc
- Multiple vulnerabilities in IBM FlashSystem (and TMS RAMSAN) 710, 720, 810, and 820 systems
- Input validation error in IBM ProtecTIER
- Gentoo update for GNU C Library
- Slackware Linux update for glibc