ALAS-2014-399

Related Vulnerabilities: CVE-2014-5119  

An off-by-one heap-based buffer overflow flaw was found in glibc's internal __gconv_translit_find() function. An attacker able to make an application call the iconv_open() function with a specially crafted argument could possibly use this flaw to execute arbitrary code with the privileges of that application.

ALAS-2014-399


Amazon Linux AMI Security Advisory: ALAS-2014-399
Advisory Release Date: 2014-09-03 14:44 Pacific
Advisory Updated Date: 2014-09-19 11:57 Pacific
Severity: Important
References: CVE-2014-5119 

Issue Overview:

An off-by-one heap-based buffer overflow flaw was found in glibc's internal __gconv_translit_find() function. An attacker able to make an application call the iconv_open() function with a specially crafted argument could possibly use this flaw to execute arbitrary code with the privileges of that application.


Affected Packages:

glibc


Issue Correction:
Run yum update glibc to update your system.

New Packages:
i686:
    glibc-devel-2.17-55.85.amzn1.i686
    glibc-2.17-55.85.amzn1.i686
    glibc-utils-2.17-55.85.amzn1.i686
    nscd-2.17-55.85.amzn1.i686
    glibc-headers-2.17-55.85.amzn1.i686
    glibc-debuginfo-common-2.17-55.85.amzn1.i686
    glibc-static-2.17-55.85.amzn1.i686
    glibc-common-2.17-55.85.amzn1.i686
    glibc-debuginfo-2.17-55.85.amzn1.i686

src:
    glibc-2.17-55.85.amzn1.src

x86_64:
    glibc-debuginfo-2.17-55.85.amzn1.x86_64
    glibc-common-2.17-55.85.amzn1.x86_64
    glibc-utils-2.17-55.85.amzn1.x86_64
    glibc-2.17-55.85.amzn1.x86_64
    glibc-static-2.17-55.85.amzn1.x86_64
    glibc-debuginfo-common-2.17-55.85.amzn1.x86_64
    glibc-headers-2.17-55.85.amzn1.x86_64
    nscd-2.17-55.85.amzn1.x86_64
    glibc-devel-2.17-55.85.amzn1.x86_64