First published: Mon Jan 04 2021(Updated: )
GNU glibc is vulnerable to a denial of service, caused by a buffer over-read in iconv feature. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a SIGSEGV.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU glibc | <=2.32 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 | |
NetApp ONTAP Select Deploy administration utility | ||
NetApp Service Processor | ||
Broadcom Fabric Operating System | ||
Netapp A250 Firmware | ||
Netapp A250 | ||
Netapp 500f Firmware | ||
Netapp 500f | ||
Debian Debian Linux | =10.0 | |
Netapp Baseboard Management Controller A250 Firmware | ||
Netapp Baseboard Management Controller A250 | ||
Netapp Baseboard Management Controller 500f Firmware | ||
Netapp Baseboard Management Controller 500f | ||
All of | ||
Netapp A250 Firmware | ||
Netapp A250 | ||
All of | ||
Netapp 500f Firmware | ||
Netapp 500f | ||
IBM Security Verify Access | <=10.0.0 | |
debian/glibc | 2.31-13+deb11u11 2.31-13+deb11u10 2.36-9+deb12u8 2.36-9+deb12u7 2.40-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-25013 is a vulnerability in the iconv feature of GNU glibc that can be exploited by a remote attacker to cause a denial of service.
CVE-2019-25013 has a severity value of 7.5, which is considered high.
IBM Security Verify Access 10.0.0, GNU glibc up to version 2.32, Fedoraproject Fedora 32 and 33, NetApp ONTAP Select Deploy administration utility, NetApp Service Processor, Broadcom Fabric Operating System, Netapp Baseboard Management Controller A250 Firmware, and Debian Debian Linux 10.0 are affected by CVE-2019-25013.
CVE-2019-25013 can be exploited by sending a specially-crafted request to the iconv feature of GNU glibc, causing a SIGSEGV.
Yes, you can find more information about CVE-2019-25013 at the following references: [IBM X-Force Exchange](https://exchange.xforce.ibmcloud.com/vulnerabilities/194579), [IBM Support](https://www.ibm.com/support/pages/node/6538418), [Apache Kafka Mailing List](https://lists.apache.org/thread.html/r32d767ac804e9b8aad4355bb85960a6a1385eab7afff549a5e98660f@%3Cjira.kafka.apache.org%3E).