QID 352247

Date Published: 2021-03-26

QID 352247: Amazon Linux Security Advisory for glibc: ALAS2-2021-1615

<DIV> Issue Overview:

A flaw was found in glibc's iconv() functionality. This flaw allows an attacker capable of supplying a crafted sequence of characters to an application using iconv() to convert from ISO-2022-JP-3 to cause an assertion failure. The highest threat from this vulnerability is to system availability. (CVE-2021-3326 )

</DIV>

Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Please refer to Amazon advisory ALAS-2021-1615 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 352247

    Software Advisories
    Advisory ID Software Component Link
    ALAS-2021-1615 Amazon Linux 2 glibc (2.26-42.amzn2) on aarch64 URL Logo alas.aws.amazon.com/AL2/ALAS-2021-1615.html
    ALAS-2021-1615 Amazon Linux 2 glibc (2.26-42.amzn2) on i686 URL Logo alas.aws.amazon.com/AL2/ALAS-2021-1615.html
    ALAS-2021-1615 Amazon Linux 2 glibc (2.26-42.amzn2) on src URL Logo alas.aws.amazon.com/AL2/ALAS-2021-1615.html
    ALAS-2021-1615 Amazon Linux 2 glibc (2.26-42.amzn2) on x86_64 URL Logo alas.aws.amazon.com/AL2/ALAS-2021-1615.html