FreeBSD iconv (3) NULL pointer indirect reference and cross-border array Access Vulnerability

Source: Internet
Author: User

FreeBSD iconv (3) NULL pointer indirect reference and cross-border array Access Vulnerability

Release date:
Updated on:

Affected Systems:
FreeBSD
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-3951
 
FreeBSD is a UNIX operating system and an important branch of Unix developed from BSD, javasbsd, and 4.4BSD. The iconv (3) API allows you to convert text data encoded by one character set to another. HZ is the GB2312 character set encoding in simplified Chinese. VIQR is a Vietnamese character encoding.
 
The NULL pointer indirect reference vulnerability exists in the initialization code of the HZ module. The VIQR module's initialization Code has the cross-border array access vulnerability, which can cause the application to crash when calling iconv_open (3) that involves HZ or VIQR.

A simple tutorial on Rsync synchronization on FreeBSD 8

FreeBSD8.2 system installation Salt

Create FreeBSD system custom installation ISO

FreeBSD builds NAT and configures multiple VLANs on a single Nic
 
<* Source: Manuel Mausz

Link: ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-14:15.iconv.asc
*>

Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
 
FreeBSD
-------
FreeBSD has released a Security Bulletin (FreeBSD-SA-14: 15. iconv) and patches for this:
FreeBSD-SA-14: 15. iconv: iconv (3) NULL pointer dereference and out-of-bounds array access
Link: ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-14:15.iconv.asc

This article permanently updates the link address:

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.