cbcvebase.
CVE-2019-25013
published 2021-01-04

CVE-2019-25013: The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a…

PriorityP429medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
3.54%
88.0th percentile
The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read.

Affected

14 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianglibc< glibc 2.31-9 (bookworm)glibc 2.31-9 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
gnuglibc<= 2.32
gnuglibc>= 0 < 2.31-92.31-9
gnuglibc>= 0 < 2.31-92.31-9
gnuglibc>= 0 < 2.31-92.31-9
gnuglibc>= 0 < 2.31-92.31-9
gnuglibc>= 0 < 2.27-3ubuntu1.52.27-3ubuntu1.5
gnuglibc>= 0 < 2.31-0ubuntu9.72.31-0ubuntu9.7
gnuglibc>= 0 < 2.23-0ubuntu11.3+esm32.23-0ubuntu11.3+esm3
msrccm1_glibc_2.28-16_on_cbl_mariner_1.0
paloaltopan-os

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_msrc5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.