HIGH 7.5 Microsoft
CVE-2021-3326
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier when processing invalid input sequences in the ISO-2022-JP-3 encoding fails an assertion in the code path and aborts the program potentially resulting in a denial of service.
Microsoft Security Update 2021-Jan: The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier when processing invalid input sequences in the ISO-2022-JP-3 encoding fails an assertion in the code path and aborts the program potentially resulting in a denial of service.
Affected Products
- glibc-2.28-17.cm1.x86_64.rpm on CBL Mariner 1.0 x64
- glibc-devel-2.28-17.cm1.x86_64.rpm on CBL Mariner 1.0 x64
- glibc-lang-2.28-17.cm1.x86_64.rpm on CBL Mariner 1.0 x64
- glibc-i18n-2.28-17.cm1.x86_64.rpm on CBL Mariner 1.0 x64
- glibc-iconv-2.28-17.cm1.x86_64.rpm on CBL Mariner 1.0 x64
- glibc-tools-2.28-17.cm1.x86_64.rpm on CBL Mariner 1.0 x64
- glibc-nscd-2.28-17.cm1.x86_64.rpm on CBL Mariner 1.0 x64
- glibc-2.28-17.cm1.aarch64.rpm on CBL Mariner 1.0 ARM
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-3326
- https://nvd.nist.gov/vuln/detail/CVE-2021-3326
This high severity vulnerability with a CVSS score of 7.5 was published on 2021-01-12 via Microsoft. Affected: glibc-2.28-17.cm1.x86_64.rpm on CBL Mariner 1.0 x64, glibc-devel-2.28-17.cm1.x86_64.rpm on CBL Mariner 1.0 x64, glibc-lang-2.28-17.cm1.x86_64.rpm on CBL Mariner 1.0 x64 and 5 more.
vulnfeed aggregates 10539 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.