Vulnerability CVE-2016-10228: Information
Description
The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with the -c option, enters an infinite loop when processing invalid multi-byte input sequences, leading to a denial of service.
Severity: MEDIUM (5.9) Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
glibc | sisyphus | 2.26.0.124.98f244e-alt1 | 2.38.0.66.ge1135387de-alt1 | ALT-PU-2017-2833-1 | 197446 | Fixed |
glibc | sisyphus_e2k | 2.35.0.234.3f63f9dfe1-alt1.E2K.27.020.2 | 2.35.0.234.3f63f9dfe1-alt1.E2K.27.020.4 | ALT-PU-2024-1492-1 | - | Fixed |
glibc | p10 | 2.26.0.124.98f244e-alt1 | 2.32-alt5.p10.2 | ALT-PU-2017-2833-1 | 197446 | Fixed |
glibc | p9 | 2.27-alt14 | 2.27-alt14 | ALT-PU-2021-2862-1 | 285569 | Fixed |
glibc | c10f1 | 2.26.0.124.98f244e-alt1 | 2.32-alt5.p10.2 | ALT-PU-2017-2833-1 | 197446 | Fixed |
glibc | c9f2 | 2.27-alt14 | 2.27-alt14 | ALT-PU-2021-2880-1 | 285733 | Fixed |
glibc | c7 | 2.17-alt5.M70C.13 | 2.17-alt5.M70C.14 | ALT-PU-2017-2198-1 | 188136 | Fixed |