Infinite Loop Vulnerability in GNU C Library Affects glibc by Sourceware
CVE-2020-27618
5.5MEDIUM
Summary
The iconv function in the GNU C Library (glibc) versions 2.32 and earlier is susceptible to an infinite loop when it processes invalid multi-byte input sequences in certain encodings (IBM1364, IBM1371, IBM1388, IBM1390, IBM1399). This flaw prevents the input state from advancing correctly, potentially leading to a denial of service in applications utilizing this library. Proper sanitization of input and adherence to encoding standards is crucial in mitigating this issue.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved