iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a multibyte character value of "0xffff" to the iconv function when converting IBM930 encoded data to UTF-8.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade glibcUpgrade eglibc | Jul 30, 2024 | Dec 5, 2014 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jul 23, 2015 |
| Gentoo Linux | — | Upgrade sys-libs/glibc. | Oct 30, 2017 | Dec 5, 2014 |
| Suse | — | Upgrade glibc-32bitUpgrade glibc-infoUpgrade glibc-x86Upgrade glibc-profileUpgrade glibc-profile-32bitUpgrade glibc-profile-x86Upgrade glibc-locale-x86Upgrade glibc-localeUpgrade glibc-devel-32bitUpgrade glibc-i18ndataUpgrade glibc-locale-32bitUpgrade nscdUpgrade glibcUpgrade glibc-develUpgrade glibc-html | Feb 17, 2015 | Sep 2, 2014 |
| Ubuntu | — | Upgrade libc6 | Nov 8, 2024 | Dec 5, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub