Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3326

Опубликовано: 27 янв. 2021
Источник: debian

Описание

The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
glibcfixed2.31-10package

Примечания

  • https://bugs.chromium.org/p/project-zero/issues/detail?id=2146

  • https://sourceware.org/bugzilla/show_bug.cgi?id=27256

  • https://sourceware.org/pipermail/libc-alpha/2021-January/122058.html

  • Fixed by: https://sourceware.org/git/?p=glibc.git;a=commit;h=7d88c6142c6efc160c0ee5e4f85cde382c072888

  • When fixing the issue for older suites make sure to not open up CVE-2021-43396

  • and make a complete fix.

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.

CVSS3: 7.5
redhat
больше 4 лет назад

The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.

CVSS3: 7.5
nvd
больше 4 лет назад

The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.

CVSS3: 7.5
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 7.5
github
около 3 лет назад

The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.