CVE-2016-10228: Input Validation
GNU C Library (glibc) is vulnerable to a denial of service, caused by an error in the iconv program. By processing invalid multi-byte input sequences, a remote attacker could exploit this vulnerability to cause the application to enter into an infinite loop.
Other sources
The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with the -c option, enters an infinite loop when processing invalid multi-byte input sequences, leading to a denial of service.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2016-10228.
What is the severity of CVE-2016-10228?
The severity of CVE-2016-10228 is medium with a CVSS score of 5.9.
Which software versions are affected by CVE-2016-10228?
The GNU C Library (glibc) versions 2.31 and earlier, as well as IBM Security Verify Access version 10.0.0, are affected by CVE-2016-10228.
What is the impact of CVE-2016-10228?
CVE-2016-10228 can lead to a denial of service due to an infinite loop when processing invalid multi-byte input sequences.
Where can I find more information about CVE-2016-10228?
You can find more information about CVE-2016-10228 in the following references: [link1], [link2], [link3].