ZeroHour

CVE-2020-27618

PoC
CVSS 3.1
5.5 medium
EPSS
<1%p57
Published
()
Modified
Description

The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service, a different vulnerability from CVE-2016-10228.

Vendors
gnunetapporacledebian
Products
glibc, ontap select deploy administration utility, a250 firmware, 500f firmware, h410c firmware, h300s firmware, h500s firmware, h700s firmware, h300e firmware, h500e firmware, h700e firmware, h410s firmware
Weakness
CWE-835
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.