Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-29562

Опубликовано: 19 нояб. 2020
Источник: redhat
CVSS3: 4.8

Описание

The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irreversible character, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.

A denial of service flaw was found in the way glibc's iconv function handled UCS4 text containing an irreversible character. This flaw causes an application compiled with glibc and using the vulnerable function to terminate with an assertion, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5glibcNot affected
Red Hat Enterprise Linux 6glibcNot affected
Red Hat Enterprise Linux 7glibcNot affected
Red Hat Enterprise Linux 8glibcNot affected
Red Hat Enterprise Linux 9glibcNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20->CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=1905217glibc: assertion failure in iconv when converting invalid UCS4

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
около 5 лет назад

The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irreversible character, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.

CVSS3: 4.8
nvd
около 5 лет назад

The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irreversible character, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.

CVSS3: 4.8
debian
около 5 лет назад

The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2 ...

CVSS3: 4.8
github
больше 3 лет назад

The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irreversible character, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.

suse-cvrf
почти 5 лет назад

Security update for glibc

4.8 Medium

CVSS3