FreeBSD iconv (3) NULL pointer indirect reference and cross-border array Access Vulnerability
Release date:
Updated on:
Affected Systems:
FreeBSD
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-3951
FreeBSD is a UNIX operating system and an important branch of Unix developed from BSD, javasbsd, and 4.4BSD. The iconv (3) API allows you to convert text data encoded by one character set to another. HZ is the GB2312 character set encoding in simplified Chinese. VIQR is a Vietnamese character encoding.
The NULL pointer indirect reference vulnerability exists in the initialization code of the HZ module. The VIQR module's initialization Code has the cross-border array access vulnerability, which can cause the application to crash when calling iconv_open (3) that involves HZ or VIQR.
A simple tutorial on Rsync synchronization on FreeBSD 8
FreeBSD8.2 system installation Salt
Create FreeBSD system custom installation ISO
FreeBSD builds NAT and configures multiple VLANs on a single Nic
<* Source: Manuel Mausz
Link: ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-14:15.iconv.asc
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
FreeBSD
-------
FreeBSD has released a Security Bulletin (FreeBSD-SA-14: 15. iconv) and patches for this:
FreeBSD-SA-14: 15. iconv: iconv (3) NULL pointer dereference and out-of-bounds array access
Link: ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-14:15.iconv.asc
This article permanently updates the link address: