oss-sec mailing list archives

Re: glibc iconv crash with ISO-2022-JP-3


From: Siddhesh Poyarekar <siddhesh.poyarekar () gmail com>
Date: Thu, 28 Jan 2021 08:24:10 +0530

On Wed, 27 Jan 2021 at 21:08, Siddhesh Poyarekar
<siddhesh.poyarekar () gmail com> wrote:

On Wed, 27 Jan 2021 at 21:03, Tavis Ormandy <taviso () gmail com> wrote:
The impact is just that you can't open your mail client, because it
crashes as soon as it sees the subject.

Upstream bug: https://sourceware.org/bugzilla/show_bug.cgi?id=27256
Patch: https://sourceware.org/pipermail/libc-alpha/2021-January/122058.html

FYI, I have filed a CVE request for this with Mitre.

This is now CVE-2021-3326.


Current thread: