cbcvebase.
CVE-2024-2961
published 2024-04-17

CVE-2024-2961: The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the…

high7.3CVSS 3.1
AVLACLPRNUINSUCLILAH
EXPLOIT
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianglibc< glibc 2.36-9+deb12u6 (bookworm)glibc 2.36-9+deb12u6 (bookworm)
eglibceglibc>= 0 < 2.19-0ubuntu6.15+esm32.19-0ubuntu6.15+esm3
gnuglibc>= 0 < 2.31-13+deb11u92.31-13+deb11u9
gnuglibc>= 0 < 2.36-9+deb12u62.36-9+deb12u6
gnuglibc>= 0 < 2.37-182.37-18
gnuglibc>= 0 < 2.37-182.37-18
gnuglibc>= 0 < 2.23-0ubuntu11.3+esm62.23-0ubuntu11.3+esm6
gnuglibc>= 0 < 2.27-3ubuntu1.6+esm22.27-3ubuntu1.6+esm2
gnuglibc>= 2.1.93 < 2.402.40
matrix-orgmatrix-sdk-crypto>= 0.7.0 < 0.7.10.7.1
the_gnu_c_libraryglibc>= 2.1.93 < 2.402.40

CVSS provenance

nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
osv9.8CRITICAL
vulncheck7.3HIGH