CVE-2024-2961
high · 7.3A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
7.3
CVSS
88.3%
EPSS (exploit prob.)
100th
EPSS percentile
2024-04-17
Published
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Weaknesses
CWE-787
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| gnu | glibc | >= 2.1.93, < 2.40 |
| netapp | active_iq_unified_manager | all versions |
| debian | debian_linux | 10.0 |
| netapp | hci_h300s_firmware | all versions |
| netapp | hci_h300s | all versions |
| netapp | hci_h500s_firmware | all versions |
| netapp | hci_h500s | all versions |
| netapp | hci_h700s_firmware | all versions |
| netapp | hci_h700s | all versions |
| netapp | hci_h410s_firmware | all versions |
| netapp | hci_h410s | all versions |
| netapp | hci_h410c_firmware | all versions |
| netapp | hci_h410c | all versions |
| netapp | hci_h610c_firmware | all versions |
| netapp | hci_h610c | all versions |
| netapp | hci_h610s_firmware | all versions |
| netapp | hci_h610s | all versions |
| netapp | hci_h615c_firmware | all versions |
| netapp | hci_h615c | all versions |
| netapp | hci_compute_node | all versions |
| netapp | hci_compute_node | all versions |
| netapp | ontap_select_deploy_administration_utility | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://www.openwall.com/lists/oss-security/2024/04/17/9
- http://www.openwall.com/lists/oss-security/2024/04/18/4
- http://www.openwall.com/lists/oss-security/2024/04/24/2
- http://www.openwall.com/lists/oss-security/2024/05/27/1
- http://www.openwall.com/lists/oss-security/2024/05/27/2
- http://www.openwall.com/lists/oss-security/2024/05/27/3
- http://www.openwall.com/lists/oss-security/2024/05/27/4
- http://www.openwall.com/lists/oss-security/2024/05/27/5
- http://www.openwall.com/lists/oss-security/2024/05/27/6
- http://www.openwall.com/lists/oss-security/2024/07/22/5
- https://lists.debian.org/debian-lts-announce/2024/05/msg00001.html
- https://lists.fedoraproject.org/archives/list/[email protected]/message/BTJFBGHDYG5PEIFD5WSSSKSFZ2AZWC5N/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/P3I4KYS6EU6S7QZ47WFNTPVAHFIUQNEL/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/YAMJQI3Y6BHWV3CUTYBXOZONCUJNOB2Z/
- https://security.netapp.com/advisory/ntap-20240531-0002/
- https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0004
- http://www.openwall.com/lists/oss-security/2024/04/17/9
- http://www.openwall.com/lists/oss-security/2024/04/18/4
- http://www.openwall.com/lists/oss-security/2024/04/24/2
- http://www.openwall.com/lists/oss-security/2024/05/27/1
- http://www.openwall.com/lists/oss-security/2024/05/27/2
- http://www.openwall.com/lists/oss-security/2024/05/27/3
- http://www.openwall.com/lists/oss-security/2024/05/27/4
- http://www.openwall.com/lists/oss-security/2024/05/27/5
- http://www.openwall.com/lists/oss-security/2024/05/27/6
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-2961