CVE-2021-43396 - CVE House
Back to Database
Status published High CVE-2021-43396

In iconvdata/iso-2022-jp-3.c in the GNU C Library (aka glibc) 2.34,...

Vulnerability Description

In iconvdata/iso-2022-jp-3.c in the GNU C Library (aka glibc) 2.34, remote attackers can force iconv() to emit a spurious '\0' character via crafted ISO-2022-JP-3 data that is accompanied by an internal state reset. This may affect data integrity in certain iconv() use cases. NOTE: the vendor states "the bug cannot be invoked through user input and requires iconv to be invoked with a NULL inbuf, which ought to require a separate application bug to do so unintentionally. Hence there's no security impact to the bug.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-43396

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

glibc, communications cloud native core binding support function, communications cloud native core network function cloud native environment, communications cloud native core network repository function, communications cloud native core security edge protection proxy, communications cloud native core unified data repository, enterprise operations monitor
Vulnerable Versions:
2.34, 22.1.3, 22.1.0, 22.1.2, 22.2.0, 22.1.1, 4.3, 4.4, 5.0

Timeline

Official Publish: November 4th, 2021
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.