NEWS: Mention CVE-2019-25013

(cherry picked from commit 18b640c57094236e6c991ba16f87467085a1d55a)
This commit is contained in:
Siddhesh Poyarekar 2021-01-08 09:17:06 +05:30 committed by Dmitry V. Levin
parent 32022774db
commit b2229db87d

3
NEWS
View File

@ -9,6 +9,9 @@ Version 2.32.1
Security related changes:
CVE-2019-25013: A buffer overflow has been fixed in the iconv function when
invoked with EUC-KR input containing invalid multibyte input sequences.
CVE-2020-27618: An infinite loop has been fixed in the iconv program when
invoked with input containing redundant shift sequences in the IBM1364,
IBM1371, IBM1388, IBM1390, or IBM1399 character sets.