CVE-2024-2961

Updated: 2024-04-22 09:21:46.832159

Description:

The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0
CVSS Version 3.x HIGH 8.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU glibc 2.34 8.8 HIGH Released CLSA-2024:1718023873 2024-06-10 10:18:16
CentOS 6 ELS glibc 2.12 8.8 HIGH Released CLSA-2024:1717694505 2024-06-15 11:27:07
CentOS 7 ELS glibc 2.17 8.8 HIGH Released CLSA-2024:1720027216 2024-07-19 04:55:13
CentOS 8.4 ELS glibc 2.28 8.8 HIGH Released CLSA-2024:1718790660 2024-06-19 10:13:58
CentOS 8.5 ELS glibc 2.28 8.8 HIGH Released CLSA-2024:1718024371 2024-06-10 10:18:17
CentOS Stream 8 ELS glibc 2.28 8.8 HIGH Released CLSA-2024:1718900000 2024-06-20 14:21:31
CloudLinux 6 ELS glibc 2.12 8.8 HIGH Released CLSA-2024:1717693595 2024-06-15 11:27:06
Oracle Linux 6 ELS glibc 2.12 8.8 HIGH Released CLSA-2024:1717694198 2024-06-06 14:23:24
Ubuntu 16.04 ELS glibc 2.23-0 8.8 HIGH Released CLSA-2024:1717691587 2024-06-06 14:23:25
Ubuntu 18.04 ELS glibc 2.27-3 8.8 HIGH Released CLSA-2024:1719569907 2024-06-28 10:17:30