DSA-3012-1 eglibc -- security update

Related Vulnerabilities: CVE-2014-5119  

Tavis Ormandy discovered a heap-based buffer overflow in the transliteration module loading code in eglibc, Debian's version of the GNU C Library. As a result, an attacker who can supply a crafted destination character set argument to iconv-related character conversation functions could achieve arbitrary code execution. This update removes support of loadable gconv transliteration modules. Besides the security vulnerability, the module loading code had functionality defects which prevented it from working for the intended purpose. For the stable distribution (wheezy), this problem has been fixed in version 2.13-38+deb7u4. We recommend that you upgrade your eglibc packages.

Debian Security Advisory

DSA-3012-1 eglibc -- security update

Date Reported:
27 Aug 2014
Affected Packages:
eglibc
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2014-5119.
More information:

Tavis Ormandy discovered a heap-based buffer overflow in the transliteration module loading code in eglibc, Debian's version of the GNU C Library. As a result, an attacker who can supply a crafted destination character set argument to iconv-related character conversation functions could achieve arbitrary code execution.

This update removes support of loadable gconv transliteration modules. Besides the security vulnerability, the module loading code had functionality defects which prevented it from working for the intended purpose.

For the stable distribution (wheezy), this problem has been fixed in version 2.13-38+deb7u4.

We recommend that you upgrade your eglibc packages.