CVE-2014-0475
published 2014-07-29CVE-2014-0475: Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand…
PriorityP433medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.69%
84.3th percentile
Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecified impact via a .. (dot dot) in a (1) LC_*, (2) LANG, or other locale environment variable.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.19-6 (bookworm) | glibc 2.19-6 (bookworm) |
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.1 | 2.19-0ubuntu6.1 |
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.3 | 2.19-0ubuntu6.3 |
| gnu | glibc | <= 2.19 | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5rvh-fh5r-rhfv: Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2
ghsa_unreviewed·2022-05-17
CVE-2014-0475 [MEDIUM] CWE-22 GHSA-5rvh-fh5r-rhfv: Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2
Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecified impact via a .. (dot dot) in a (1) LC_*, (2) LANG, or other locale environment variable.
OSV
eglibc vulnerability
osv·2014-08-29·CVSS 6.8
CVE-2014-5119 [MEDIUM] eglibc vulnerability
eglibc vulnerability
Tavis Ormandy and John Haxby discovered that the GNU C Library contained an
off-by-one error when performing transliteration module loading. A local
attacker could exploit this to gain administrative privileges.
(CVE-2014-5119)
USN-2306-1 fixed vulnerabilities in the GNU C Library. On Ubuntu 10.04 LTS
and Ubuntu 12.04 LTS the security update for CVE-2014-0475 caused a
regression with localplt on PowerPC. This update fixes the problem. We
apologize for the inconvenience.
OSV
eglibc vulnerabilities
osv·2014-08-04·CVSS 7.5
CVE-2013-4357 [HIGH] eglibc vulnerabilities
eglibc vulnerabilities
Maksymilian Arciemowicz discovered that the GNU C Library incorrectly
handled the getaddrinfo() function. An attacker could use this issue to
cause a denial of service. This issue only affected Ubuntu 10.04 LTS.
(CVE-2013-4357)
It was discovered that the GNU C Library incorrectly handled the
getaddrinfo() function. An attacker could use this issue to cause a denial
of service. This issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS.
(CVE-2013-4458)
Stephane Chazelas discovered that the GNU C Library incorrectly handled
locale environment variables. An attacker could use this issue to possibly
bypass certain restrictions such as the ForceCommand restrictions in
OpenSSH. (CVE-2014-0475)
David Reid, Glyph Lefkowitz, and Alex Gaynor discovered that the GNU C
L
OSV
CVE-2014-0475: Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2
osv·2014-07-29·CVSS 6.8
CVE-2014-0475 [MEDIUM] CVE-2014-0475: Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2
Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecified impact via a .. (dot dot) in a (1) LC_*, (2) LANG, or other locale environment variable.
Ubuntu
GNU C Library regression
vendor_ubuntu·2014-09-08·CVSS 7.5
CVE-2013-4357 [HIGH] GNU C Library regression
Title: GNU C Library regression
Summary: USN-2306-1 introduced a regression in the GNU C Library.
USN-2306-1 fixed vulnerabilities in the GNU C Library. On Ubuntu 10.04 LTS,
the fix for CVE-2013-4357 introduced a memory leak in getaddrinfo. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Maksymilian Arciemowicz discovered that the GNU C Library incorrectly
handled the getaddrinfo() function. An attacker could use this issue to
cause a denial of service. This issue only affected Ubuntu 10.04 LTS.
(CVE-2013-4357)
It was discovered that the GNU C Library incorrectly handled the
getaddrinfo() function. An attacker could use this issue to cause a denial
of service. This issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS.
(CVE-2013-4458)
Ubuntu
GNU C Library vulnerability
vendor_ubuntu·2014-08-29·CVSS 6.8
CVE-2014-5119 [MEDIUM] GNU C Library vulnerability
Title: GNU C Library vulnerability
Summary: Certain applications could be made to crash or run programs as an
administrator.
Tavis Ormandy and John Haxby discovered that the GNU C Library contained an
off-by-one error when performing transliteration module loading. A local
attacker could exploit this to gain administrative privileges.
(CVE-2014-5119)
USN-2306-1 fixed vulnerabilities in the GNU C Library. On Ubuntu 10.04 LTS
and Ubuntu 12.04 LTS the security update for CVE-2014-0475 caused a
regression with localplt on PowerPC. This update fixes the problem. We
apologize for the inconvenience.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
GNU C Library regression
vendor_ubuntu·2014-08-05·CVSS 7.5
[HIGH] GNU C Library regression
Title: GNU C Library regression
Summary: USN-2306-1 introduced a regression in the GNU C Library.
USN-2306-1 fixed vulnerabilities in the GNU C Library. On Ubuntu 10.04 LTS,
the security update cause a regression in certain environments that use
the Name Service Caching Daemon (nscd), such as those configured for LDAP
or MySQL authentication. In these environments, the nscd daemon may need
to be stopped manually for name resolution to resume working so that
updates can be downloaded, including environments configured for unattended
updates.
We apologize for the inconvenience.
Original advisory details:
Maksymilian Arciemowicz discovered that the GNU C Library incorrectly
handled the getaddrinfo() function. An attacker could use this issue to
cause a denial of service. This issue only
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2014-08-04·CVSS 7.5
CVE-2013-4357 [HIGH] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in the GNU C Library.
Maksymilian Arciemowicz discovered that the GNU C Library incorrectly
handled the getaddrinfo() function. An attacker could use this issue to
cause a denial of service. This issue only affected Ubuntu 10.04 LTS.
(CVE-2013-4357)
It was discovered that the GNU C Library incorrectly handled the
getaddrinfo() function. An attacker could use this issue to cause a denial
of service. This issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS.
(CVE-2013-4458)
Stephane Chazelas discovered that the GNU C Library incorrectly handled
locale environment variables. An attacker could use this issue to possibly
bypass certain restrictions such as the ForceCommand restrictions in
OpenSSH. (CVE-201
Red Hat
glibc: directory traversal in LC_* locale handling
vendor_redhat·2014-07-09·CVSS 6.8
CVE-2014-0475 [MEDIUM] CWE-22 glibc: directory traversal in LC_* locale handling
glibc: directory traversal in LC_* locale handling
Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecified impact via a .. (dot dot) in a (1) LC_*, (2) LANG, or other locale environment variable.
A directory traveral flaw was found in the way glibc loaded locale files. An attacker able to make an application use a specially crafted locale name value (for example, specified in an LC_* environment variable) could possibly use this flaw to execute arbitrary code with the privileges of that application.
Debian
CVE-2014-0475: glibc - Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc...
vendor_debian·2014·CVSS 6.8
CVE-2014-0475 [MEDIUM] CVE-2014-0475: glibc - Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc...
Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecified impact via a .. (dot dot) in a (1) LC_*, (2) LANG, or other locale environment variable.
Scope: local
bookworm: resolved (fixed in 2.19-6)
bullseye: resolved (fixed in 2.19-6)
forky: resolved (fixed in 2.19-6)
sid: resolved (fixed in 2.19-6)
trixie: resolved (fixed in 2.19-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0475 glibc: directory traversal in LC_* locale handling [fedora-all]
bugzilla·2014-07-11·CVSS 6.8
CVE-2014-0475 [MEDIUM] CVE-2014-0475 glibc: directory traversal in LC_* locale handling [fedora-all]
CVE-2014-0475 glibc: directory traversal in LC_* locale handling [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple
Bugzilla
CVE-2014-0475 glibc: directory traversal in LC_* locale handling
bugzilla·2014-05-28·CVSS 6.8
CVE-2014-0475 [MEDIUM] CVE-2014-0475 glibc: directory traversal in LC_* locale handling
CVE-2014-0475 glibc: directory traversal in LC_* locale handling
It was found that glibc suffers from a directory traversal vulnerability when processing paths in LC_* variables. As a result, you can set arbitrary locale specifications in certain environment variables, such as LC_ALL. With certain programs, these environment variables are inherited -- this is particularly a problem for suid programs. A program that runs suid to any other user (including root) could inherit these environment variables and load malicious locale specifications, which could result in the execution of arbitrary code.
Certain programs do not use locale specifications (such as mount, su, passwd), and some sanitize environment variables contain certain characters (for instance, if sudo encounters a whitelisted e
http://linux.oracle.com/errata/ELSA-2015-0092.htmlhttp://www.debian.org/security/2014/dsa-2976http://www.mandriva.com/security/advisories?name=MDVSA-2014:152http://www.openwall.com/lists/oss-security/2014/07/10/7http://www.openwall.com/lists/oss-security/2014/07/14/6http://www.securityfocus.com/bid/68505http://www.securitytracker.com/id/1030569https://rhn.redhat.com/errata/RHSA-2014-1110.htmlhttps://security.gentoo.org/glsa/201602-02https://sourceware.org/bugzilla/show_bug.cgi?id=17137http://linux.oracle.com/errata/ELSA-2015-0092.htmlhttp://www.debian.org/security/2014/dsa-2976http://www.mandriva.com/security/advisories?name=MDVSA-2014:152http://www.openwall.com/lists/oss-security/2014/07/10/7http://www.openwall.com/lists/oss-security/2014/07/14/6http://www.securityfocus.com/bid/68505http://www.securitytracker.com/id/1030569https://rhn.redhat.com/errata/RHSA-2014-1110.htmlhttps://security.gentoo.org/glsa/201602-02https://sourceware.org/bugzilla/show_bug.cgi?id=17137
2014-07-29
Published