[Bug 1929105] Re: CVE-2021-3326: The iconv app in glibc when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion & aborts

Steve Beattie 1929105 at bugs.launchpad.net
Sat Sep 18 05:04:22 UTC 2021


** Bug watch added: Sourceware.org Bugzilla #27256
   https://sourceware.org/bugzilla/show_bug.cgi?id=27256

** Also affects: glibc via
   https://sourceware.org/bugzilla/show_bug.cgi?id=27256
   Importance: Unknown
       Status: Unknown

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to glibc in Ubuntu.
https://bugs.launchpad.net/bugs/1929105

Title:
  CVE-2021-3326: The iconv app in glibc when processing invalid input
  sequences in the ISO-2022-JP-3 encoding, fails an assertion  & aborts

Status in GLibC:
  Unknown
Status in glibc package in Ubuntu:
  Fix Released
Status in glibc source package in Bionic:
  New
Status in glibc source package in Focal:
  New
Status in glibc source package in Groovy:
  Won't Fix

Bug description:
  The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and
  earlier, when processing invalid input sequences in the ISO-2022-JP-3
  encoding, fails an assertion in the code path and aborts the program,
  potentially resulting in a denial of service.

  Ref.: https://ubuntu.com/security/CVE-2021-3326

To manage notifications about this bug go to:
https://bugs.launchpad.net/glibc/+bug/1929105/+subscriptions




More information about the foundations-bugs mailing list