Vulnerability CVE-2020-27618: Information
Description
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service, a different vulnerability from CVE-2016-10228.
Severity: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
glibc | sisyphus | 2.32-alt1 | 2.38.0.76.e9f05fa1c6-alt1 | ALT-PU-2020-3524-1 | 263483 | Fixed |
glibc | sisyphus_e2k | 2.35.0.234.3f63f9dfe1-alt1.E2K.27.020.2 | 2.35.0.234.3f63f9dfe1-alt1.E2K.27.020.4 | ALT-PU-2024-1492-1 | - | Fixed |
glibc | sisyphus_riscv64 | 2.34.0.39.024a7-alt1.rv64 | 2.38.0.76.e9f05fa1c6-alt1 | ALT-PU-2021-4728-1 | - | Fixed |
glibc | p10 | 2.32-alt1 | 2.32-alt5.p10.3 | ALT-PU-2020-3524-1 | 263483 | Fixed |
glibc | p9 | 2.27-alt14 | 2.27-alt14 | ALT-PU-2021-2862-1 | 285569 | Fixed |
glibc | c10f1 | 2.32-alt1 | 2.32-alt5.p10.3 | ALT-PU-2020-3524-1 | 263483 | Fixed |
glibc | c9f2 | 2.27-alt14 | 2.27-alt14 | ALT-PU-2021-2880-1 | 285733 | Fixed |
glibc | p11 | 2.32-alt1 | 2.38.0.76.e9f05fa1c6-alt1 | ALT-PU-2020-3524-1 | 263483 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://sourceware.org/bugzilla/show_bug.cgi?id=19519#c21 |
|
https://sourceware.org/bugzilla/show_bug.cgi?id=26224 |
|
https://security.netapp.com/advisory/ntap-20210401-0006/ |
|
GLSA-202107-07 |
|
https://www.oracle.com/security-alerts/cpujan2022.html |
|
https://www.oracle.com/security-alerts/cpuapr2022.html |
|
[debian-lts-announce] 20221017 [SECURITY] [DLA 3152-1] glibc security update |
|