Vulnerability Bulletins

DSA-3012 eglibc - security update

   
Affected software Debian
 
Tavis Ormandy discovered a heap-based buffer overflow in thetransliteration module loading code in eglibc, Debians version of theGNU C Library. As a result, an attacker who can supply a crafteddestination character set argument to iconv-related characterconversation functions could achieve arbitrary code execution.

More info:

https://www.debian.org/security/2014/dsa-3012