Out-of-bounds read in GNU C Library (glibc) - CVE-2019-25013
Published: January 4, 2021 / Updated: February 4, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition in GNU C Library within the iconv feature when processing multi-byte input sequences in the EUC-KR encoding. A remote attacker can pass specially crafted input to the application, trigger out-of-bounds read error and perform a denial of service (DoS) attack.
Affected software
Arch Linux
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Server 11
F5OS
SUSE Manager Retail Branch Server
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Enterprise Storage
CentOS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Module for Basesystem
Ubuntu
openEuler
Fedora
Isolation Segment
VMware Tanzu Application Service for VMs
Service Telemetry Framework
Netcool Operations Insight
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Transformation Advisor
SIMATIC S7-1500 TM MFP - BIOS
cflinuxfs3
Tanzu Greenplum for Kubernetes
Data Computing Appliance (DCA)
Robotic Process Automation for Cloud Pak
Red Hat OpenShift Serverless
Windows Container Support for Red Hat OpenShift
OpenShift Virtualization
VMware Tanzu Operations Manager
Cloud Pak for Security (CP4S)
RecoverPoint for Virtual Machines
Red Hat OpenShift Jaeger
BIG-IQ Centralized Management
IBM Security Verify Access
Juniper Junos Space
BIG-IP LTM
BIG-IP FPS
BIG-IP Analytics
BIG-IP PEM
BIG-IP GTM
BIG-IP APM
BIG-IP ASM
BIG-IP AFM
BIG-IP Link Controller
BIG-IP DNS
BIG-IP AAM
BIG-IP Advanced WAF
BIG-IP SSLO
BIG-IP DDHD
BIG-IP
libc6 (Ubuntu package)
glibc-32bit
glibc-devel-32bit
glibc-locale-32bit
glibc-info
glibc-locale
glibc-html
glibc-i18ndata
glibc-profile
glibc
nscd
glibc-devel
glibc-debuginfo-32bit
glibc-debugsource
glibc-profile-32bit
glibc-debuginfo
glibc (Red Hat package)
nscd-debuginfo
glibc-devel-debuginfo-32bit
glibc-devel-debuginfo
glibc-locale-debuginfo
glibc-locale-debuginfo-32bit
glibc-utils-src-debugsource
glibc-utils-debuginfo
glibc-utils
glibc-locale-base-debuginfo
glibc-locale-base
glibc-extra-debuginfo
glibc-extra
glibc-devel-static
glibc-locale-base-32bit-debuginfo
glibc-locale-base-32bit
glibc-devel-32bit-debuginfo
glibc-32bit-debuginfo
glibc-help
glibc-all-langpacks
nss_modules
libnsl
glibc-common
glibc-benchtests
glibc-debugutils
glibc-locale-source
glibc-nss-devel
Web Terminal
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
How to mitigate CVE-2019-25013
Red Hat OpenShift Serverless - update to 1.16.0
Cloud Pak for Security (CP4S) - update to 1.8.0.0
Red Hat OpenShift Jaeger - addressed in versions 1.17.9, 1.20.4
Windows Container Support for Red Hat OpenShift - update to 2.0.1
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
libc6 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2.27-3ubuntu1.5, 2.31-0ubuntu9.7, 2.34-0ubuntu3.2
Web Terminal - update to 1.3
Netcool Operations Insight - update to 1.6.8
Tanzu Greenplum for Kubernetes - update to 2.0.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.1.3
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0
VMware Tanzu Operations Manager - update to 2.10.52
glibc-32bit - addressed in versions 2.11.3-17.110.43.1, 2.22-126.1, 2.26-13.56.1
glibc-devel-32bit - addressed in versions 2.11.3-17.110.43.1, 2.22-126.1, 2.26-13.56.1
glibc-locale-32bit - addressed in versions 2.11.3-17.110.43.1, 2.22-126.1
glibc-info - addressed in versions 2.11.3-17.110.43.1, 2.22-126.1, 2.26-13.56.1
glibc-locale - addressed in versions 2.11.3-17.110.43.1, 2.22-126.1, 2.26-13.56.1
glibc-html - addressed in versions 2.11.3-17.110.43.1, 2.22-126.1
glibc-i18ndata - addressed in versions 2.11.3-17.110.43.1, 2.22-126.1, 2.26-13.56.1
glibc-profile - addressed in versions 2.11.3-17.110.43.1, 2.22-126.1, 2.26-13.56.1
glibc - addressed in versions 2.11.3-17.110.43.1, 2.22-126.1, 2.26-13.56.1
nscd - addressed in versions 2.11.3-17.110.43.1, 2.22-126.1, 2.26-13.56.1
glibc-devel - addressed in versions 2.11.3-17.110.43.1, 2.22-126.1, 2.26-13.56.1
glibc-debuginfo-32bit - addressed in versions 2.11.3-17.110.43.1, 2.22-126.1
glibc-debugsource - addressed in versions 2.11.3-17.110.43.1, 2.22-126.1, 2.26-13.56.1
glibc-profile-32bit - addressed in versions 2.11.3-17.110.43.1, 2.22-126.1
glibc-debuginfo - addressed in versions 2.11.3-17.110.43.1, 2.22-126.1, 2.26-13.56.1
glibc (Red Hat package) - addressed in versions 2.17-322.el7_9, 2.28-151.el8
nscd-debuginfo - addressed in versions 2.22-126.1, 2.26-13.56.1
glibc-devel-debuginfo-32bit - update to 2.22-126.1
glibc-devel-debuginfo - addressed in versions 2.22-126.1, 2.26-13.56.1
glibc-locale-debuginfo - update to 2.22-126.1
glibc-locale-debuginfo-32bit - update to 2.22-126.1
glibc-utils-src-debugsource - update to 2.26-13.56.1
glibc-utils-debuginfo - update to 2.26-13.56.1
glibc-utils - update to 2.26-13.56.1
glibc-locale-base-debuginfo - update to 2.26-13.56.1
glibc-locale-base - update to 2.26-13.56.1
glibc-extra-debuginfo - update to 2.26-13.56.1
glibc-extra - update to 2.26-13.56.1
glibc-devel-static - update to 2.26-13.56.1
glibc-locale-base-32bit-debuginfo - update to 2.26-13.56.1
glibc-locale-base-32bit - update to 2.26-13.56.1
glibc-devel-32bit-debuginfo - update to 2.26-13.56.1
glibc-32bit-debuginfo - update to 2.26-13.56.1
glibc-help - update to 2.28-52
glibc-all-langpacks - update to 2.28-52
nss_modules - update to 2.28-52
libnsl - update to 2.28-52
glibc-debugsource - update to 2.28-52
glibc-debuginfo - update to 2.28-52
glibc-common - update to 2.28-52
glibc-devel - update to 2.28-52
nscd - update to 2.28-52
glibc-benchtests - update to 2.28-52
glibc-debugutils - update to 2.28-52
glibc-locale-source - update to 2.28-52
glibc - update to 2.28-52
glibc-nss-devel - update to 2.28-52
glibc - addressed in versions 2.31-5.fc32, 2.32-3.fc33
IBM Cloud Transformation Advisor - update to 3.10.0
Data Computing Appliance (DCA) - update to 4.3.0.0
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
Robotic Process Automation for Cloud Pak - update to 21.0.6
Juniper Junos Space - update to 21.2R1
External References
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4Y6TX47P47KABSFOL26FLDNVCWXDKDEZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TVCUNLQ3HXGS4VPUQKWTJGRAW2KTFGXS/
- https://sourceware.org/bugzilla/show_bug.cgi?id=24973
- https://sourceware.org/git/?p=glibc.git;a=commit;h=ee7a3144c9922808181009b7b3e50e852fb4999b
Related Security Bulletins
- Denial of service in glibc
- CentOS 7 update for glibc
- Arch Linux update for glibc
- Arch Linux update for lib32-glibc
- Denial of service in glibc implementation in F5 BIG-IP and F5OS
- Multiple vulnerabilities in Red Hat OpenShift Jaeger
- Multiple vulnerabilities in Windows Container Support for Red Hat OpenShift
- Multiple vulnerabilities in Red Hat OpenShift Jaeger
- Gentoo update for glibc
- Amazon Linux AMI update for glibc
- Multiple vulnerabilities in OpenShift Serverless
- Multiple vulnerabilities in Junos Space
- Multiple vulnerabilities in Red Hat Web Terminal
- Multiple vulnerabilities in Dell EMC Unity
- Multiple vulnerabilities in IBM Security Verify Access
- Multiple vulnerabilities in Cloud Foundry cflinuxfs3
- SUSE update for glibc
- Ubuntu update for glibc
- Multiple vulnerabilities in Red Hat Service Telemetry Framework
- Multiple vulnerabilities in IBM Cloud Pak for Security
- SUSE update for glibc
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Ubuntu update for glibc
- Red Hat Enterprise Linux 7 update for glibc
- Red Hat Enterprise Linux 8 update for glibc
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- SUSE update for glibc
- VMware Tanzu products update for GNU C Library
- Multiple vulnerabilities in Siemens SIMATIC S7-1500 TM MFP - BIOS
- Multiple vulnerabilities in IBM Netcool Operations Insight
- SUSE update for glibc
- openEuler update for glibc
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.1
- Multiple vulnerabilities in OpenShift Virtualization 4.8
- Multiple vulnerabilities in OpenShift Virtualization 2.6
- Fedora 33 update for glibc
- Fedora 32 update for glibc
- Dell RecoverPoint for Virtual Machines update for third-party components