Reachable Assertion in GNU C Library (glibc) - CVE-2020-29562

 

Reachable Assertion in GNU C Library (glibc) - CVE-2020-29562

Published: December 4, 2020 / Updated: January 19, 2021


Vulnerability identifier: #VU49670
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-29562
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a reachable assertion when converting UCS4 text containing an irreversible character in the iconv function in the GNU C Library (aka glibc or libc6). A remote attacker can pass specially crafted data to the library, trigger an assertion failure and preform a denial of service attack.


Affected software

GNU C Library (glibc)
Arch Linux
Gentoo Linux
SUSE Linux Enterprise Server 11
SUSE Manager Retail Branch Server
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Development Tools
Ubuntu
Fedora
SIMATIC S7-1500 TM MFP - BIOS
cflinuxfs3
glibc-html
glibc-info
glibc-locale
glibc-i18ndata
glibc-profile
glibc
nscd
glibc-devel
glibc-debuginfo-32bit
glibc-devel-32bit
glibc-debugsource
glibc-profile-32bit
glibc-debuginfo
glibc-32bit
glibc-locale-32bit
glibc-devel-static
nscd-debuginfo
glibc-locale-debuginfo-32bit
glibc-locale-debuginfo
glibc-devel-debuginfo-32bit
glibc-devel-debuginfo
glibc-extra-debuginfo
glibc-32bit-debuginfo
glibc-locale-base-debuginfo
glibc-locale-base
glibc-extra
glibc-utils
glibc-utils-debuginfo
glibc-utils-src-debugsource
glibc-locale-base-32bit-debuginfo
glibc-locale-base-32bit
glibc-devel-32bit-debuginfo
libc6 (Ubuntu package)
sys-libs/glibc
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)

How to mitigate CVE-2020-29562

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

cflinuxfs3 - update to 0.275.0
glibc-html - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1
glibc-info - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc-locale - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc-i18ndata - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc-profile - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
nscd - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc-devel - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc-debuginfo-32bit - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1
glibc-devel-32bit - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc-debugsource - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc-profile-32bit - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1
glibc-debuginfo - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc-32bit - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc-locale-32bit - addressed in versions 2.11.3-17.110.43.1, 2.22-114.8.3, 2.22-126.1
glibc-devel-static - addressed in versions 2.22-114.8.3, 2.26-13.56.1
nscd-debuginfo - addressed in versions 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc-locale-debuginfo-32bit - addressed in versions 2.22-114.8.3, 2.22-126.1
glibc-locale-debuginfo - addressed in versions 2.22-114.8.3, 2.22-126.1
glibc-devel-debuginfo-32bit - addressed in versions 2.22-114.8.3, 2.22-126.1
glibc-devel-debuginfo - addressed in versions 2.22-114.8.3, 2.22-126.1, 2.26-13.56.1
glibc-extra-debuginfo - update to 2.26-13.56.1
glibc-32bit-debuginfo - update to 2.26-13.56.1
glibc-locale-base-debuginfo - update to 2.26-13.56.1
glibc-locale-base - update to 2.26-13.56.1
glibc-extra - update to 2.26-13.56.1
glibc-utils - update to 2.26-13.56.1
glibc-utils-debuginfo - update to 2.26-13.56.1
glibc-utils-src-debugsource - update to 2.26-13.56.1
glibc-locale-base-32bit-debuginfo - update to 2.26-13.56.1
glibc-locale-base-32bit - update to 2.26-13.56.1
glibc-devel-32bit-debuginfo - update to 2.26-13.56.1
libc6 (Ubuntu package) - addressed in versions 2.27-3ubuntu1.5, 2.31-0ubuntu9.7, 2.34-0ubuntu3.2
glibc - update to 2.31-5.fc32
sys-libs/glibc - update to 2.32-r5
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007

External References

Related Security Bulletins