CVE-2020-27618: Medium severity ibm security verify access oidc provider vulnerability
GNU C Library (aka glibc or libc6) is vulnerable to a denial of service, caused by an error when processing some invalid inputs from several IBM character sets in the iconv function. By sending invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, IBM1399 encodings, a local authenticated attacker could exploit this vulnerability to cause the application to enter into an infinite loop.
Other sources
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service, a different vulnerability from CVE-2016-10228.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-27618?
CVE-2020-27618 is a vulnerability in the GNU C Library (glibc) that can lead to a denial of service.
How does CVE-2020-27618 affect IBM Security Verify Access?
IBM Security Verify Access version 10.0.0 is affected by CVE-2020-27618.
Is NetApp ONTAP Select Deploy administration utility affected by CVE-2020-27618?
Yes, NetApp ONTAP Select Deploy administration utility is affected by CVE-2020-27618.
What is the severity of CVE-2020-27618?
CVE-2020-27618 has a severity level of medium (5.5).
How can I fix CVE-2020-27618?
To fix CVE-2020-27618, update your affected software to a version that includes the necessary patches.