CVE-2014-5119 describes an off-by-one error in the GNU C Library (glibc) affecting Debian Linux distributions. This vulnerability allows remote attackers to trigger a denial of service or potentially execute arbitrary code by manipulating the CHARSET environment variable and glibc's gconv transliteration modules. With a CVSS score of 7.5, it is considered highly severe, requiring low attack complexity and no authentication, with potential impacts on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, an ExploitDB entry (EDB-34421) exists, indicating public exploit code for a NUL byte off-by-one, and it has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.20CPE matchmatch criteria | cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.