CVE-2014-5119: Debian Linux

High severity, CVSS 7.5. EPSS: 17% chance of exploitation in the next 30 days.

Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment variable and gconv transliteration modules.

Affected products

  • Debian Debian Linux: version 7.0 only
  • GNU Glibc: before 2.20 (fixed in 2.20)

Published 2014-08-29. Last modified 2026-06-17.