CVE-2014-5119
published 2014-08-29CVE-2014-5119: Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of…
PriorityP356high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
18.10%
96.9th percentile
Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment variable and gconv transliteration modules.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | glibc | < glibc 2.19-10 (bookworm) | glibc 2.19-10 (bookworm) |
| eglibc | eglibc | >= 0 < 2.19-0ubuntu6.3 | 2.19-0ubuntu6.3 |
| gnu | glibc | < 2.20 | 2.20 |
| gnu | glibc | >= 0 < 2.19-10 | 2.19-10 |
| gnu | glibc | >= 0 < 2.19-10 | 2.19-10 |
| gnu | glibc | >= 0 < 2.19-10 | 2.19-10 |
| gnu | glibc | >= 0 < 2.19-10 | 2.19-10 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
vendor_redhat7.5HIGH
vendor_ubuntu6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jv4w-947j-grmm: Off-by-one error in the __gconv_translit_find function in gconv_trans
ghsa_unreviewed·2022-05-13
CVE-2014-5119 [HIGH] GHSA-jv4w-947j-grmm: Off-by-one error in the __gconv_translit_find function in gconv_trans
Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment variable and gconv transliteration modules.
OSV
CVE-2014-5119: Off-by-one error in the __gconv_translit_find function in gconv_trans
osv·2014-08-29·CVSS 7.5
CVE-2014-5119 [HIGH] CVE-2014-5119: Off-by-one error in the __gconv_translit_find function in gconv_trans
Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment variable and gconv transliteration modules.
OSV
eglibc vulnerability
osv·2014-08-29·CVSS 6.8
CVE-2014-5119 [MEDIUM] eglibc vulnerability
eglibc vulnerability
Tavis Ormandy and John Haxby discovered that the GNU C Library contained an
off-by-one error when performing transliteration module loading. A local
attacker could exploit this to gain administrative privileges.
(CVE-2014-5119)
USN-2306-1 fixed vulnerabilities in the GNU C Library. On Ubuntu 10.04 LTS
and Ubuntu 12.04 LTS the security update for CVE-2014-0475 caused a
regression with localplt on PowerPC. This update fixes the problem. We
apologize for the inconvenience.
Ubuntu
GNU C Library vulnerability
vendor_ubuntu·2014-08-29·CVSS 6.8
CVE-2014-5119 [MEDIUM] GNU C Library vulnerability
Title: GNU C Library vulnerability
Summary: Certain applications could be made to crash or run programs as an
administrator.
Tavis Ormandy and John Haxby discovered that the GNU C Library contained an
off-by-one error when performing transliteration module loading. A local
attacker could exploit this to gain administrative privileges.
(CVE-2014-5119)
USN-2306-1 fixed vulnerabilities in the GNU C Library. On Ubuntu 10.04 LTS
and Ubuntu 12.04 LTS the security update for CVE-2014-0475 caused a
regression with localplt on PowerPC. This update fixes the problem. We
apologize for the inconvenience.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
glibc: off-by-one error leading to a heap-based buffer overflow flaw in __gconv_translit_find()
vendor_redhat·2014-07-14·CVSS 7.5
CVE-2014-5119 [HIGH] CWE-193 glibc: off-by-one error leading to a heap-based buffer overflow flaw in __gconv_translit_find()
glibc: off-by-one error leading to a heap-based buffer overflow flaw in __gconv_translit_find()
Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment variable and gconv transliteration modules.
An off-by-one heap-based buffer overflow flaw was found in glibc's internal __gconv_translit_find() function. An attacker able to make an application call the iconv_open() function with a specially crafted argument could possibly use this flaw to execute arbitrary code with the privileges of that application.
Package: glibc (Red Hat Enterprise Linux Extended Update Support 5.6) - Affected
Debian
CVE-2014-5119: glibc - Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C...
vendor_debian·2014·CVSS 7.5
CVE-2014-5119 [HIGH] CVE-2014-5119: glibc - Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C...
Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment variable and gconv transliteration modules.
Scope: local
bookworm: resolved (fixed in 2.19-10)
bullseye: resolved (fixed in 2.19-10)
forky: resolved (fixed in 2.19-10)
sid: resolved (fixed in 2.19-10)
trixie: resolved (fixed in 2.19-10)
No detection rules found.
Bugzilla
CVE-2014-5119 glibc: out-of-bounds NUL write in iconv_open [fedora-all]
bugzilla·2014-08-13·CVSS 7.5
CVE-2014-5119 [HIGH] CVE-2014-5119 glibc: out-of-bounds NUL write in iconv_open [fedora-all]
CVE-2014-5119 glibc: out-of-bounds NUL write in iconv_open [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora
Bugzilla
CVE-2014-5119 glibc: off-by-one error leading to a heap-based buffer overflow flaw in __gconv_translit_find()
bugzilla·2014-07-14·CVSS 7.5
CVE-2014-5119 [HIGH] CVE-2014-5119 glibc: off-by-one error leading to a heap-based buffer overflow flaw in __gconv_translit_find()
CVE-2014-5119 glibc: off-by-one error leading to a heap-based buffer overflow flaw in __gconv_translit_find()
Tavis Ormandy reported an off-by-one error leading to a heap-based buffer overflow flaw in glibc's __gconv_translit_find() function. This could be triggered by setting the CHARSET environment variable to a malicious value. This could possibly lead to code execution as root if a set user ID (setuid) root application used this environment variable without sanitizing its value.
References:
http://www.openwall.com/lists/oss-security/2014/07/14/1
http://www.openwall.com/lists/oss-security/2014/07/14/2
Discussion:
MITRE assigned CVE-2014-5119 to this issue:
http://seclists.org/oss-sec/2014/q3/358
Upstream bug:
https://sourceware.org/bugzilla/show_bug.cgi?id=17187
---
*** Bug 11
http://googleprojectzero.blogspot.com/2014/08/the-poisoned-nul-byte-2014-edition.htmlhttp://linux.oracle.com/errata/ELSA-2015-0092.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00017.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1118.htmlhttp://seclists.org/fulldisclosure/2014/Aug/69http://secunia.com/advisories/60345http://secunia.com/advisories/60358http://secunia.com/advisories/60441http://secunia.com/advisories/61074http://secunia.com/advisories/61093http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-5119http://www-01.ibm.com/support/docview.wss?uid=swg21685604http://www.debian.org/security/2014/dsa-3012http://www.mandriva.com/security/advisories?name=MDVSA-2014:175http://www.openwall.com/lists/oss-security/2014/07/14/1http://www.openwall.com/lists/oss-security/2014/08/13/5http://www.securityfocus.com/bid/68983http://www.securityfocus.com/bid/69738https://code.google.com/p/google-security-research/issues/detail?id=96https://rhn.redhat.com/errata/RHSA-2014-1110.htmlhttps://security.gentoo.org/glsa/201602-02https://sourceware.org/bugzilla/show_bug.cgi?id=17187http://googleprojectzero.blogspot.com/2014/08/the-poisoned-nul-byte-2014-edition.htmlhttp://linux.oracle.com/errata/ELSA-2015-0092.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00017.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1118.htmlhttp://seclists.org/fulldisclosure/2014/Aug/69http://secunia.com/advisories/60345http://secunia.com/advisories/60358http://secunia.com/advisories/60441http://secunia.com/advisories/61074http://secunia.com/advisories/61093http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-5119http://www-01.ibm.com/support/docview.wss?uid=swg21685604http://www.debian.org/security/2014/dsa-3012http://www.mandriva.com/security/advisories?name=MDVSA-2014:175http://www.openwall.com/lists/oss-security/2014/07/14/1http://www.openwall.com/lists/oss-security/2014/08/13/5http://www.securityfocus.com/bid/68983http://www.securityfocus.com/bid/69738https://code.google.com/p/google-security-research/issues/detail?id=96https://rhn.redhat.com/errata/RHSA-2014-1110.htmlhttps://security.gentoo.org/glsa/201602-02https://sourceware.org/bugzilla/show_bug.cgi?id=17187
2014-08-29
Published