GNU glibc Locale Environment Handling Directory Traversal Vulnerability
BID:68505
Info
GNU glibc Locale Environment Handling Directory Traversal Vulnerability
| Bugtraq ID: | 68505 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-0475 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 09 2014 12:00AM |
| Updated: | Jul 05 2016 09:26PM |
| Credit: | Stephane Chazelas |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise Server 10 SP3 LTSS Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 GNU glibc 0 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 6 |
| Not Vulnerable: | |
Discussion
GNU glibc Locale Environment Handling Directory Traversal Vulnerability
GNU glibc is prone to a directory-traversal vulnerability.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to read arbitrary files in the context of the application. This may aid in further attacks.
GNU glibc is prone to a directory-traversal vulnerability.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to read arbitrary files in the context of the application. This may aid in further attacks.
Solution / Fix
GNU glibc Locale Environment Handling Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.