[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    Re: [oss-security] glibc iconv crash with ISO-2022-JP-3
From:       Siddhesh Poyarekar <siddhesh.poyarekar () gmail ! com>
Date:       2021-01-28 3:06:10
Message-ID: CAAHN_R0By+J-YoqZ-8amdM9SrZ8_EnHdTgiVtufPPZF-ZwEgPw () mail ! gmail ! com
[Download RAW message or body]

On Wed, 27 Jan 2021 at 21:08, Siddhesh Poyarekar
<siddhesh.poyarekar@gmail.com> wrote:
>
> On Wed, 27 Jan 2021 at 21:03, Tavis Ormandy <taviso@gmail.com> wrote:
> > The impact is just that you can't open your mail client, because it
> > crashes as soon as it sees the subject.
> >
> > Upstream bug: https://sourceware.org/bugzilla/show_bug.cgi?id=27256
> > Patch: https://sourceware.org/pipermail/libc-alpha/2021-January/122058.html
>
> FYI, I have filed a CVE request for this with Mitre.

This is now CVE-2021-3326.
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic