The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irreversible character, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.
{
"unresolved_ranges": [
{
"cpe": "cpe:2.3:a:netapp:e-series_santricity_os_controller:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "11.0.0"
},
{
"last_affected": "11.60.3"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "32"
}
],
"source": "CPE_FIELD"
}
]
}{
"cpe": "cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "2.30"
},
{
"last_affected": "2.32"
}
],
"source": "CPE_FIELD"
}