Lucene search

K
ibmIBM79504390973D2889C577A7D974CDE7EF4BE96C6C947E52BCC35462A61EB2CBD1
HistoryFeb 23, 2022 - 5:02 p.m.

Security Bulletin: IBM QRadar SIEM is affected by a GNU C Library (glibc) vulnerability (CVE-2014-5119)

2022-02-2317:02:11
www.ibm.com
10

0.012 Low

EPSS

Percentile

84.9%

Summary

A security vulnerability have been discovered in GNU C Library (glibc) component bundled with IBM QRadar SIEM.

Vulnerability Details

CVE-ID: CVE-2014-5119

DESCRIPTION: The GNU C Library (glibc) is vulnerable to a heap-based buffer overflow, caused by an off-by-one error in the __gconv_translit_find() function. By setting the CHARSET environment variable to a malicious value, a local attacker could exploit this vulnerability to overflow a buffer and execute arbitrary code on the system with root privileges.

CVSS Base Score: 7.2
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/95044 for more information
CVSS Environmental Score:*: Undefined
CVSS Vector: CVSS Vector: (AV:L/AC:L/Au:N/C:C/I:C/A:C)

Affected Products and Versions

    • IBM QRadar SIEM 7.2.3 Patch 4 and below.
  • IBM QRadar SIEM 7.1 MR2 Patch 8 and below.
  • IBM QRadar Vulnerability Manager 7.2.3 Patch 4 and below.
  • IBM QRadar Risk Manager 7.2.3 Patch 4 and below.
  • IBM QRadar Risk Manager 7.1 MR2 Patch 8 and below.

Remediation/Fixes

The recommended solution is to apply the fix for each named product as soon as practical. Please see below for information about the fixes available.

Product Remediation/First Fix

Workarounds and Mitigations

None

**