ZeroHour

CVE-2021-43396

PoC ×2
CVSS 3.1
7.5 high
EPSS
3%p88
Published
()
Modified
Description

In iconvdata/iso-2022-jp-3.c in the GNU C Library (aka glibc) 2.34, remote attackers can force iconv() to emit a spurious '\0' character via crafted ISO-2022-JP-3 data that is accompanied by an internal state reset. This may affect data integrity in certain iconv() use cases. NOTE: the vendor states "the bug cannot be invoked through user input and requires iconv to be invoked with a NULL inbuf, which ought to require a separate application bug to do so unintentionally. Hence there's no security impact to the bug.

Vendors
gnuoracle
Products
glibc, communications cloud native core binding support function, communications cloud native core network function cloud native environment, communications cloud native core network repository function, communications cloud native core security edge protection proxy, communications cloud native core unified data repository, enterprise operations monitor
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.