[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2021-1656 --- glibc

ID: oval:org.secpod.oval:def:1700651Date: (C)2021-06-29   (M)2023-12-20
Class: PATCHFamily: unix




In the GNU C Library through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match. A flaw was found in glibc. If an attacker provides the iconv function with invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, IBM1399 encodings, it fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service

Platform:
Amazon Linux 2
Product:
glibc
Reference:
ALAS2-2021-1656
CVE-2019-9169
CVE-2020-27618
CVE    2
CVE-2019-9169
CVE-2020-27618

© SecPod Technologies