ALAS-2015-495 --- glibcID: oval:org.secpod.oval:def:1200119 | Date: (C)2015-12-28 (M)2024-02-19 |
Class: PATCH | Family: unix |
An out-of-bounds read flaw was found in the way glibc"s iconv function converted certain encoded data to UTF-8. An attacker able to make an application call the iconv function with a specially crafted argument could use this flaw to crash that application. It was found that the files back end of Name Service Switch did not isolate iteration over an entire database from key-based look-up API calls. An application performing look-ups on a database while iterating over it could enter an infinite loop, leading to a denial of service
Platform: |
Amazon Linux AMI |