CVE-2016-10228
published 2017-03-02CVE-2016-10228: The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the destination encoding (TRANSLATE or…
PriorityP428medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
4.01%
89.5th percentile
The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with the -c option, enters an infinite loop when processing invalid multi-byte input sequences, leading to a denial of service.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | glibc | < glibc 2.31-5 (bookworm) | glibc 2.31-5 (bookworm) |
| debian | glibc | < glibc 2.31-3 (bookworm) | glibc 2.31-3 (bookworm) |
| gnu | glibc | <= 2.25 | — |
| gnu | glibc | <= 2.32 | — |
| gnu | glibc | >= 0 < 2.31-5 | 2.31-5 |
| gnu | glibc | >= 0 < 2.31-3 | 2.31-3 |
| gnu | glibc | >= 0 < 2.31-5 | 2.31-5 |
| gnu | glibc | >= 0 < 2.31-3 | 2.31-3 |
| gnu | glibc | >= 0 < 2.31-5 | 2.31-5 |
| gnu | glibc | >= 0 < 2.31-3 | 2.31-3 |
| gnu | glibc | >= 0 < 2.31-5 | 2.31-5 |
| gnu | glibc | >= 0 < 2.31-3 | 2.31-3 |
| gnu | glibc | >= 0 < 2.27-3ubuntu1.5 | 2.27-3ubuntu1.5 |
| gnu | glibc | >= 0 < 2.31-0ubuntu9.7 | 2.31-0ubuntu9.7 |
| gnu | glibc | >= 0 < 2.23-0ubuntu11.3+esm3 | 2.23-0ubuntu11.3+esm3 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_glibc_2.28-18_on_cbl_mariner_1.0 | — | — |
| oracle | communications_cloud_native_core_service_communication_proxy | — | — |
| paloalto | pan-os | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.9MEDIUM
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
vendor_paloalto·2024-04-10·CVSS 9.8
CVE-2015-5739 [CRITICAL] PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2015-5739 This CVE is fixed in PAN-OS 11.0.4, and all later PAN-OS versions. CVE-2016-10228 This CVE is fixed in PAN-OS 11.1.3, and all later PAN-OS versions. CVE-2017-8923 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2017-9120 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2018-25009 This CVE is fixed in PAN-OS 10.2.8, 11.0.4, 11.1.3, and all later PAN-OS versions. CVE-2
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
CISA ICS
Siemens SIMATIC S7-1500 TM MFP BIOS
cisa_ics·2023-06-15·CVSS 5.9
[MEDIUM] Siemens SIMATIC S7-1500 TM MFP BIOS
ICS Advisory
##
Siemens SIMATIC S7-1500 TM MFP BIOS
Release DateJune 15, 2023
Alert CodeICSA-23-166-10
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely / low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 TM MFP
- Vulnerabilities: Improper Input Validation, Out-of-bounds Read, Use After Free, Out-of-bounds Write, Infinite Loop, Reachable Assertion, Off-by-one Error, Incorrect Default Permissions, Double Fr
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2022-12-08·CVSS 5.9
CVE-2019-25013 [MEDIUM] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in GNU C Library.
Jan Engelhardt, Tavis Ormandy, and others discovered that the GNU C Library
iconv feature incorrectly handled certain input sequences. An attacker
could possibly use this issue to cause the GNU C Library to hang or crash,
resulting in a denial of service. (CVE-2016-10228, CVE-2019-25013,
CVE-2020-27618)
It was discovered that the GNU C Library did not properly handled DNS
responses when ENDS0 is enabled. An attacker could possibly use this issue
to cause fragmentation-based attacks. (CVE-2017-12132)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2022-03-01·CVSS 5.9
CVE-2021-3999 [MEDIUM] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in GNU C Library.
Jan Engelhardt, Tavis Ormandy, and others discovered that the GNU C Library
iconv feature incorrectly handled certain input sequences. An attacker
could possibly use this issue to cause the GNU C Library to hang or crash,
resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS
and Ubuntu 20.04 LTS. (CVE-2016-10228, CVE-2019-25013, CVE-2020-27618,
CVE-2020-29562, CVE-2021-3326)
Jason Royes and Samuel Dytrych discovered that the GNU C Library
incorrectly handled signed comparisons on ARMv7 targets. A remote attacker
could use this issue to cause the GNU C Library to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubunt
Microsoft
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier when processing invalid multi-byte input sequences in IBM1364 IBM1371 IBM1388 IBM1390 and IBM1399 encodings fails to advan
vendor_msrc·2021-02-09·CVSS 5.5
CVE-2020-27618 [MEDIUM] CWE-835 The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier when processing invalid multi-byte input sequences in IBM1364 IBM1371 IBM1388 IBM1390 and IBM1399 encodings fails to advan
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier when processing invalid multi-byte input sequences in IBM1364 IBM1371 IBM1388 IBM1390 and IBM1399 encodings fails to advance the input state which could lead to an infinite loop in applications resulting in a denial of service a different vulnerability from CVE-2016-10228.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we
Red Hat
glibc: iconv when processing invalid multi-byte input sequences fails to advance the input state, which could result in an infinite loop
vendor_redhat·2020-07-09·CVSS 5.9
CVE-2020-27618 [MEDIUM] CWE-835 glibc: iconv when processing invalid multi-byte input sequences fails to advance the input state, which could result in an infinite loop
glibc: iconv when processing invalid multi-byte input sequences fails to advance the input state, which could result in an infinite loop
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service, a different vulnerability from CVE-2016-10228.
A flaw was found in glibc. If an attacker provides the iconv function with invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, IBM1399 encodings, it fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service.
Statem
Debian
CVE-2020-27618: glibc - The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, w...
vendor_debian·2020·CVSS 5.9
CVE-2020-27618 [MEDIUM] CVE-2020-27618: glibc - The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, w...
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service, a different vulnerability from CVE-2016-10228.
Scope: local
bookworm: resolved (fixed in 2.31-5)
bullseye: resolved (fixed in 2.31-5)
forky: resolved (fixed in 2.31-5)
sid: resolved (fixed in 2.31-5)
trixie: resolved (fixed in 2.31-5)
Red Hat
glibc: iconv program can hang when invoked with the -c option
vendor_redhat·2017-01-25·CVSS 5.9
CVE-2016-10228 [MEDIUM] CWE-835 glibc: iconv program can hang when invoked with the -c option
glibc: iconv program can hang when invoked with the -c option
The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with the -c option, enters an infinite loop when processing invalid multi-byte input sequences, leading to a denial of service.
Package: compat-glibc (Red Hat Enterprise Linux 5) - Will not fix
Package: glibc (Red Hat Enterprise Linux 5) - Will not fix
Package: compat-glibc (Red Hat Enterprise Linux 6) - Will not fix
Package: glibc (Red Hat Enterprise Linux 6) - Will not fix
Package: compat-glibc (Red Hat Enterprise Linux 7) - Will not fix
Package: glibc (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2016-10228: glibc - The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, wh...
vendor_debian·2016·CVSS 5.9
CVE-2016-10228 [MEDIUM] CVE-2016-10228: glibc - The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, wh...
The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with the -c option, enters an infinite loop when processing invalid multi-byte input sequences, leading to a denial of service.
Scope: local
bookworm: resolved (fixed in 2.31-3)
bullseye: resolved (fixed in 2.31-3)
forky: resolved (fixed in 2.31-3)
sid: resolved (fixed in 2.31-3)
trixie: resolved (fixed in 2.31-3)
OSV
glibc vulnerabilities
osv·2022-12-08·CVSS 5.9
CVE-2016-10228 [MEDIUM] glibc vulnerabilities
glibc vulnerabilities
Jan Engelhardt, Tavis Ormandy, and others discovered that the GNU C Library
iconv feature incorrectly handled certain input sequences. An attacker
could possibly use this issue to cause the GNU C Library to hang or crash,
resulting in a denial of service. (CVE-2016-10228, CVE-2019-25013,
CVE-2020-27618)
It was discovered that the GNU C Library did not properly handled DNS
responses when ENDS0 is enabled. An attacker could possibly use this issue
to cause fragmentation-based attacks. (CVE-2017-12132)
GHSA
GHSA-6q5q-4c7r-7r4r: The iconv function in the GNU C Library (aka glibc or libc6) 2
ghsa_unreviewed·2022-05-24·CVSS 5.9
CVE-2020-27618 [MEDIUM] CWE-835 GHSA-6q5q-4c7r-7r4r: The iconv function in the GNU C Library (aka glibc or libc6) 2
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service, a different vulnerability from CVE-2016-10228.
GHSA
GHSA-g93f-3wq3-pq68: The iconv program in the GNU C Library (aka glibc or libc6) 2
ghsa_unreviewed·2022-05-13
CVE-2016-10228 [MEDIUM] CWE-20 GHSA-g93f-3wq3-pq68: The iconv program in the GNU C Library (aka glibc or libc6) 2
The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with the -c option, enters an infinite loop when processing invalid multi-byte input sequences, leading to a denial of service.
OSV
glibc vulnerabilities
osv·2022-03-01·CVSS 5.9
CVE-2016-10228 [MEDIUM] glibc vulnerabilities
glibc vulnerabilities
Jan Engelhardt, Tavis Ormandy, and others discovered that the GNU C Library
iconv feature incorrectly handled certain input sequences. An attacker
could possibly use this issue to cause the GNU C Library to hang or crash,
resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS
and Ubuntu 20.04 LTS. (CVE-2016-10228, CVE-2019-25013, CVE-2020-27618,
CVE-2020-29562, CVE-2021-3326)
Jason Royes and Samuel Dytrych discovered that the GNU C Library
incorrectly handled signed comparisons on ARMv7 targets. A remote attacker
could use this issue to cause the GNU C Library to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-6096)
It was discovered that the
OSV
CVE-2020-27618: The iconv function in the GNU C Library (aka glibc or libc6) 2
osv·2021-02-26·CVSS 5.9
CVE-2020-27618 [MEDIUM] CVE-2020-27618: The iconv function in the GNU C Library (aka glibc or libc6) 2
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service, a different vulnerability from CVE-2016-10228.
OSV
CVE-2016-10228: The iconv program in the GNU C Library (aka glibc or libc6) 2
osv·2017-03-02·CVSS 5.9
CVE-2016-10228 [MEDIUM] CVE-2016-10228: The iconv program in the GNU C Library (aka glibc or libc6) 2
The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with the -c option, enters an infinite loop when processing invalid multi-byte input sequences, leading to a denial of service.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-27618 glibc: iconv when processing invalid multi-byte input sequences fails to advance the input state, which could result in an infinite loop
bugzilla·2020-11-02·CVSS 5.9
CVE-2020-27618 [MEDIUM] CVE-2020-27618 glibc: iconv when processing invalid multi-byte input sequences fails to advance the input state, which could result in an infinite loop
CVE-2020-27618 glibc: iconv when processing invalid multi-byte input sequences fails to advance the input state, which could result in an infinite loop
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, IBM1399 encodings, fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service
Discussion:
External References:
https://sourceware.org/bugzilla/show_bug.cgi?id=26224
---
Created glibc tracking bugs for this issue:
Affects: fedora-all [bug 1893709]
---
This ought to be low severity similar to CVE-2016-10228.
---
Flaw summary:
When glibc iconv function/command is passed certain input, it hangs using high
HackerOne
Container scanning and Dependency scanning report leaked to unauthorized users
hackerone·2019-12-13·CVSS 5.0
[MEDIUM] Container scanning and Dependency scanning report leaked to unauthorized users
Container scanning and Dependency scanning report leaked to unauthorized users
Hi GitLab Security team
### Summary
GitLab makes the container scanning and dependency scanning information available as part of a JSON endpoint for merge requests. These reports are output of the CI job and should only be displayed if the visiting user has access to CI. However, right now GitLab displays the the container scanning and dependency scanning reports regardless of this permission, making it available to whoever has access to the merge request.
For public projects, GitLab allows to restrict CI pipelines to project members only (public pipelines disabled). However, in this case, the merge request widget still renders the scanning reports result, which is the outcome of a CI pipeline.
### Steps to
Bugzilla
CVE-2016-10228 glibc: iconv: Fix converter hangs and front end option parsing for //TRANSLIT and //IGNORE [rhel-8]
bugzilla·2019-04-30·CVSS 5.9
CVE-2016-10228 [MEDIUM] CVE-2016-10228 glibc: iconv: Fix converter hangs and front end option parsing for //TRANSLIT and //IGNORE [rhel-8]
CVE-2016-10228 glibc: iconv: Fix converter hangs and front end option parsing for //TRANSLIT and //IGNORE [rhel-8]
In bug 1427734, we fixed the specific customer reported issue with some IBM converters and input sequences. However, the converters and the option processing in the front end still need an overhaul and rework upstream. This work will be tracked upstream in SWBZ#19519 and there is some context in other Sourceware bugs linked to bug 1427734.
Discussion:
Fixed upstream with the following commit:
commit 91927b7c76437db860cd86a7714476b56bb39d07
Author: Arjun Shankar
Date: Tue Jul 7 20:31:48 2020 +0200
Rewrite iconv option parsing [BZ #19519]
This commit replaces string manipulation during `iconv_open' and iconv_prog
option parsing with a structured, flag based conversion spec
Bugzilla
CVE-2016-10228 glibc: iconv program can hang when invoked with the -c option
bugzilla·2017-03-02·CVSS 5.9
CVE-2016-10228 [MEDIUM] CVE-2016-10228 glibc: iconv program can hang when invoked with the -c option
CVE-2016-10228 glibc: iconv program can hang when invoked with the -c option
A vulnerability was found in the iconv program provided by glibc when it's invoked with the -c option. It can enter an infinite loop while parsing an invalid multi-byte sequence.
References:
http://seclists.org/oss-sec/2017/q1/538
Upstream bug:
https://sourceware.org/bugzilla/show_bug.cgi?id=19519
Discussion:
Created glibc tracking bugs for this issue:
Affects: fedora-all [bug 1428292]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2021:1585 https://access.redhat.com/errata/RHSA-2021:1585
Bugzilla
CVE-2016-10228 glibc: iconv program can hang when invoked with the -c option [fedora-all]
bugzilla·2017-03-02·CVSS 5.9
CVE-2016-10228 [MEDIUM] CVE-2016-10228 glibc: iconv program can hang when invoked with the -c option [fedora-all]
CVE-2016-10228 glibc: iconv program can hang when invoked with the -c option [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppor
http://openwall.com/lists/oss-security/2017/03/01/10http://www.securityfocus.com/bid/96525https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2022/10/msg00021.htmlhttps://security.gentoo.org/glsa/202101-20https://sourceware.org/bugzilla/show_bug.cgi?id=19519https://sourceware.org/bugzilla/show_bug.cgi?id=19519#c21https://sourceware.org/bugzilla/show_bug.cgi?id=26224https://www.oracle.com/security-alerts/cpuapr2022.htmlhttp://openwall.com/lists/oss-security/2017/03/01/10http://www.securityfocus.com/bid/96525https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2022/10/msg00021.htmlhttps://security.gentoo.org/glsa/202101-20https://sourceware.org/bugzilla/show_bug.cgi?id=19519https://sourceware.org/bugzilla/show_bug.cgi?id=19519#c21https://sourceware.org/bugzilla/show_bug.cgi?id=26224https://www.oracle.com/security-alerts/cpuapr2022.html
2017-03-02
Published