CVE-2014-5119

Public on 2014-08-29
Modified on 2014-09-19
Description
An off-by-one heap-based buffer overflow flaw was found in glibc's internal __gconv_translit_find() function. An attacker able to make an application call the iconv_open() function with a specially crafted argument could possibly use this flaw to execute arbitrary code with the privileges of that application.
Severity
Important severity
Important
CVSS v3 Base Score
6.9
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 glibc 2014-09-03 ALAS-2014-399 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv2 6.9 AV:L/AC:M/Au:N/C:C/I:C/A:C
NVD CVSSv2 7.5 AV:N/AC:L/Au:N/C:P/I:P/A:P