CVE-2014-5119

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
29/08/2014
Last modified:
12/04/2025

Description

Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment variable and gconv transliteration modules.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:* 2.20 (excluding)
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools