Lucene search

K
osvGoogleOSV:USN-6737-2
HistoryApr 29, 2024 - 11:27 a.m.

glibc vulnerability

2024-04-2911:27:19
Google
osv.dev
3
usn-6737-1
glibc
ubuntu 24.04 lts
vulnerability
denial of service
arbitrary code
gnu c library
charles fol

7.3 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

7.1 High

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

17.1%

USN-6737-1 fixed a vulnerability in the GNU C Library. This update provides
the corresponding update for Ubuntu 24.04 LTS.

Original advisory details:

Charles Fol discovered that the GNU C Library iconv feature incorrectly
handled certain input sequences. An attacker could use this issue to cause
the GNU C Library to crash, resulting in a denial of service, or possibly
execute arbitrary code.

7.3 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

7.1 High

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

17.1%