CVE-2016-10228Improper Input Validation in Glibc

Severity
5.9MEDIUMNVD
EPSS
0.4%
top 38.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 2
Latest updateApr 10

Description

The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with the -c option, enters an infinite loop when processing invalid multi-byte input sequences, leading to a denial of service.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages4 packages

Debiangnu/glibc< 2.31-3+3
Ubuntugnu/glibc< 2.27-3ubuntu1.5+2
NVDgnu/glibc2.25
Palo Altopaloalto/pan-os

🔴Vulnerability Details

5
OSV
glibc vulnerabilities2022-12-08
GHSA
GHSA-g93f-3wq3-pq68: The iconv program in the GNU C Library (aka glibc or libc6) 22022-05-13
OSV
glibc vulnerabilities2022-03-01
CVEList
CVE-2016-10228: The iconv program in the GNU C Library (aka glibc or libc6) 22017-03-02
OSV
CVE-2016-10228: The iconv program in the GNU C Library (aka glibc or libc6) 22017-03-02

📋Vendor Advisories

7
Palo Alto
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS2024-04-10
Ubuntu
GNU C Library vulnerabilities2022-12-08
Ubuntu
GNU C Library vulnerabilities2022-03-01
Microsoft
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier when processing invalid multi-byte input sequences in IBM1364 IBM1371 IBM1388 IBM1390 and IBM1399 encodings fails to advan2021-02-09
Red Hat
glibc: iconv when processing invalid multi-byte input sequences fails to advance the input state, which could result in an infinite loop2020-07-09

💬Community

4
Bugzilla
CVE-2020-27618 glibc: iconv when processing invalid multi-byte input sequences fails to advance the input state, which could result in an infinite loop2020-11-02
Bugzilla
CVE-2016-10228 glibc: iconv: Fix converter hangs and front end option parsing for //TRANSLIT and //IGNORE [rhel-8]2019-04-30
Bugzilla
CVE-2016-10228 glibc: iconv program can hang when invoked with the -c option2017-03-02
Bugzilla
CVE-2016-10228 glibc: iconv program can hang when invoked with the -c option [fedora-all]2017-03-02
CVE-2016-10228 — Improper Input Validation in GNU Glibc | cvebase