CVE-2024-2961

Public on 2024-04-17
Modified on 2024-04-18
Description
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
Severity
Important severity
Important
CVSS v3 Base Score
8.2
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 glibc 2024-04-25 ALAS-2024-1930 Fixed
Amazon Linux 2 - Core glibc 2024-04-24 ALAS2-2024-2521 Fixed
Amazon Linux 2023 glibc 2024-04-25 ALAS2023-2024-589 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
NVD CVSSv3 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H