Lucene search

K
redhatRedHatRHSA-2014:1118
HistorySep 02, 2014 - 12:00 a.m.

(RHSA-2014:1118) Important: glibc security update

2014-09-0200:00:00
access.redhat.com
30

EPSS

0.012

Percentile

84.9%

The glibc packages contain the standard C libraries used by multiple
programs on the system. These packages contain the standard C and the
standard math libraries. Without these two libraries, a Linux system cannot
function properly.

An off-by-one heap-based buffer overflow flaw was found in glibcโ€™s internal
__gconv_translit_find() function. An attacker able to make an application
call the iconv_open() function with a specially crafted argument could
possibly use this flaw to execute arbitrary code with the privileges of
that application. (CVE-2014-5119)

All glibc users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.