Lucene search

K
ibmIBM74DF7398A737BA1773A0AD3C9C1E4ABAC9F11B40697EE2587CB30E54FB5C2BAE
HistoryJun 15, 2018 - 7:01 a.m.

Security Bulletin: Vulnerabilities in glibc affect ”WebSphere Message Broker v8 HVE” and “IBM Integration Bus V9 HVE” (CVE-2014-5119)

2018-06-1507:01:48
www.ibm.com
11

EPSS

0.012

Percentile

84.9%

Summary

A glibc vulnerability was disclosed in September 2014. This bulletin addresses this vulnerability that has been referred to as “glibc: off-by-one error leading to a heap-based buffer overflow flaw in __gconv_translit_find() “. glibc is shipped with ”WebSphere Message Broker v8 HVE” and “IBM Integration Bus V9 HVE” products.

Vulnerability Details

CVE-ID: CVE-2014-5119

DESCRIPTION: The GNU C Library (glibc) is vulnerable to a heap-based buffer overflow, caused by an off-by-one error in the __gconv_translit_find() function. By setting the CHARSET environment variable to a malicious value, a local attacker could exploit this vulnerability to overflow a buffer and execute arbitrary code on the system with root privileges.

CVSS Base Score: 7.2
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/95044 for more information
CVSS Environmental Score*: Undefined
CVSS Vector: CVSS Vector: (AV:L/AC:L/Au:N/C:C/I:C/A:C)

Affected Products and Versions

  • WebSphere Message Broker v8 HVE
  • IBM Integration Bus V9 HVE

Remediation/Fixes

IBM recommends that you review your entire environment to identify vulnerable releases of glibc including your Operating Systems and take appropriate mitigation and remediation actions. Please contact your Operating System provider for more information.

Workarounds and Mitigations

None known