CVE-2019-25013

MEDIUM

GNU C Library <2.32 - Buffer Overflow

Title source: llm
STIX 2.1

Description

The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read.

References (17)

Core 17
Core References
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202107-07
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html
Issue Tracking, Patch, Third Party Advisory
https://sourceware.org/bugzilla/show_bug.cgi?id=24973

Scores

CVSS v3 5.9
EPSS 0.0080
EPSS Percentile 74.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (9)
broadcom/fabric_operating_system
debian/debian_linux 10.0
fedoraproject/fedora 32
fedoraproject/fedora 33
gnu/glibc < 2.32
netapp/500f_firmware
netapp/a250_firmware
netapp/ontap_select_deploy_administration_utility
netapp/service_processor
Published Jan 04, 2021
Tracked Since Feb 18, 2026