Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment variable and gconv transliteration modules.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Glibc | Gnu | * | 2.20 (excluding) |