QID 352399
Date Published: 2021-06-24
QID 352399: Amazon Linux Security Advisory for glibc: ALAS2-2021-1656
<DIV ID="issue_overview"> in the gnu c library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match. (
cve-2019-9169 ) a flaw was found in glibc.
If an attacker provides the iconv function with invalid multi-byte input sequences in ibm1364, ibm1371, ibm1388, ibm1390, ibm1399 encodings, it fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service. (
cve-2020-27618 ) </DIV>
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.
- ALAS2-2021-1656 -
alas.aws.amazon.com/AL2/ALAS-2021-1656.html
CVEs related to QID 352399
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS2-2021-1656 | Amazon Linux 2 |
|