Skip to content

glibc CVE-2020-27618

Low
tjkirch published GHSA-wjx7-44fw-ffxf Mar 2, 2021

Package

glibc (bottlerocket)

Affected versions

< 1.0.6

Patched versions

1.0.6

Description

If an attacker provides the iconv function with invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, IBM1399 encodings, it fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service.

Severity

Low

CVE ID

CVE-2020-27618

Weaknesses

No CWEs