Summary
Tavis Ormandy discovered a heap-based buffer overflow in the transliteration module loading code in eglibc, Debian's version of the GNU C Library. As a result, an attacker who can supply a crafted destination character set argument to iconv-related character conversation functions could achieve arbitrary code execution.
This update removes support of loadable gconv transliteration modules.
Besides the security vulnerability, the module loading code had functionality defects which prevented it from working for the intended purpose.
Solution
For the stable distribution (wheezy), this problem has been fixed in version 2.13-38+deb7u4.
We recommend that you upgrade your eglibc packages.
Affected
eglibc on Debian Linux
Detection
This check tests the installed software version using the apt package manager.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2014-5119 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities