https://seclists.org/oss-sec/2024/q2/137: The GNU C Library security advisories update for 2024-04-17: GLIBC-SA-2024-0004/CVE-2024-2961: ISO-2022-CN-EXT: fix out-of-bound writes when writing escape sequence
Published Apr 17, 2024
·Updated
Affected Software
1 affected component
GNU C Library
Frequently Asked Questions
1
What is CVE-2024-2961?
CVE-2024-2961 is a vulnerability in the GNU C Library that allows for out-of-bound writes when processing escape sequences in ISO-2022-CN-EXT.
2
What is the severity of CVE-2024-2961?
The severity of CVE-2024-2961 is considered high due to the potential for arbitrary code execution and system compromise.
3
How do I fix CVE-2024-2961?
To fix CVE-2024-2961, users should update to the latest version of the GNU C Library that includes the security patch.
4
Who is affected by CVE-2024-2961?
Any applications or systems that utilize the vulnerable versions of the GNU C Library for processing escape sequences are affected by CVE-2024-2961.
5
When was CVE-2024-2961 published?
CVE-2024-2961 was published on April 17, 2024, as part of the GNU C Library security advisories.