Oval Definition:oval:org.mitre.oval:def:27192
Revision Date:2014-12-15Version:9
Title:ELSA-2014-1110 -- glibc security update (important)
Description:An off-by-one heap-based buffer overflow flaw was found in glibc's internal __gconv_translit_find() function. An attacker able to make an application call the iconv_open() function with a specially crafted argument could possibly use this flaw to execute arbitrary code with the privileges of that application. (CVE-2014-5119) A directory traveral flaw was found in the way glibc loaded locale files. An attacker able to make an application use a specially crafted locale name value (for example, specified in an LC_* environment variable) could possibly use this flaw to execute arbitrary code with the privileges of that application. (CVE-2014-0475)
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2014-0475
CVE-2014-5119
ELSA-2014-1110
Platform(s):Oracle Linux 5
Oracle Linux 6
Product(s):glibc
Definition Synopsis
  • Oracle Linux 5 release section
  • Oracle Linux 5.x
  • AND Packages match section
  • glibc is earlier than 0:2.5-118.el5_10.3
  • OR glibc-common is earlier than 0:2.5-118.el5_10.3
  • OR glibc-devel is earlier than 0:2.5-118.el5_10.3
  • OR glibc-headers is earlier than 0:2.5-118.el5_10.3
  • OR glibc-utils is earlier than 0:2.5-118.el5_10.3
  • OR nscd is earlier than 0:2.5-118.el5_10.3
  • Oracle Linux 6 release section
  • Oracle Linux 6.x
  • AND Packages match section
  • glibc is earlier than 0:2.12-1.132.el6_5.4
  • OR glibc-common is earlier than 0:2.12-1.132.el6_5.4
  • OR glibc-devel is earlier than 0:2.12-1.132.el6_5.4
  • OR glibc-headers is earlier than 0:2.12-1.132.el6_5.4
  • OR glibc-static is earlier than 0:2.12-1.132.el6_5.4
  • OR glibc-utils is earlier than 0:2.12-1.132.el6_5.4
  • OR nscd is earlier than 0:2.12-1.132.el6_5.4
  • BACK