Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <CAAHN_R0By+J-YoqZ-8amdM9SrZ8_EnHdTgiVtufPPZF-ZwEgPw@mail.gmail.com>
Date: Thu, 28 Jan 2021 08:24:10 +0530
From: Siddhesh Poyarekar <siddhesh.poyarekar@...il.com>
To: oss-security@...ts.openwall.com
Subject: Re: glibc iconv crash with ISO-2022-JP-3

On Wed, 27 Jan 2021 at 21:08, Siddhesh Poyarekar
<siddhesh.poyarekar@...il.com> wrote:
>
> On Wed, 27 Jan 2021 at 21:03, Tavis Ormandy <taviso@...il.com> wrote:
> > The impact is just that you can't open your mail client, because it
> > crashes as soon as it sees the subject.
> >
> > Upstream bug: https://sourceware.org/bugzilla/show_bug.cgi?id=27256
> > Patch: https://sourceware.org/pipermail/libc-alpha/2021-January/122058.html
>
> FYI, I have filed a CVE request for this with Mitre.

This is now CVE-2021-3326.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.