PT-2021-5556 · Unknown+10 · Gnu C Library+10

Published

2020-07-09

·

Updated

2024-08-15

·

CVE-2020-27618

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNU C Library (glibc) versions 2.32 and earlier
Description The issue is related to the iconv function in the GNU C Library, which fails to advance the input state when processing invalid multi-byte input sequences in certain encodings, such as IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399. This could lead to an infinite loop in applications, resulting in a denial of service.
Recommendations For GNU C Library (glibc) versions 2.32 and earlier, consider updating to a version later than 2.32 to resolve the issue. As a temporary workaround, consider restricting the use of the iconv function with the affected encodings until a patch is available.

Exploit

Fix

DoS

Infinite Loop

Weakness Enumeration

Related Identifiers

ALSA-2021:1585
ALT-PU-2020-3524
ALT-PU-2021-2862
ALT-PU-2021-2880
ALT-PU-2021-3034
BDU:2021-06406
CESA-2021_1585
CVE-2020-27618
DLA-3152-1
MGASA-2021-0150
OPENSUSE-SU-2021:0358-1
OPENSUSE-SU-2021_0358-1
OPENSUSE-SU-2024:10792-1
RHSA-2021:1585
RHSA-2021_1585
RLSA-2021:1585
SUSE-SU-2021:0653-1
SUSE-SU-2021:1165-1
SUSE-SU-2021_1165-1
SUSE-SU-2022:2886-1
SUSE-SU-2024:0759-1
USN-5310-1
USN-5768-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Gnu C Library
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu