https://seclists.org/oss-sec/2024/q2/256: The GNU C Library security advisories update for 2024-04-17: GLIBC-SA-2024-0004/CVE-2024-2961: ISO-2022-CN-EXT: fix out-of-bound writes when writing escape sequence
Published May 27, 2024
·Updated
Affected Software
1 affected component
The PHP Group PHP
Frequently Asked Questions
1
What is the severity of GLIBC-SA-2024-0004/CVE-2024-2961?
The severity of GLIBC-SA-2024-0004/CVE-2024-2961 is classified as high due to the potential for out-of-bounds writes leading to various impacts.
2
How do I fix GLIBC-SA-2024-0004/CVE-2024-2961?
To fix GLIBC-SA-2024-0004/CVE-2024-2961, you should update the GNU C Library to the latest version that addresses this vulnerability.
3
What causes GLIBC-SA-2024-0004/CVE-2024-2961?
GLIBC-SA-2024-0004/CVE-2024-2961 is caused by out-of-bounds writes when writing escape sequences in ISO-2022-CN-EXT encoding.
4
What are the potential impacts of GLIBC-SA-2024-0004/CVE-2024-2961?
The potential impacts of GLIBC-SA-2024-0004/CVE-2024-2961 include data corruption and possible arbitrary code execution if exploited.
5
Which applications are affected by GLIBC-SA-2024-0004/CVE-2024-2961?
Applications that use the GNU C Library and handle controlled buffers that convert to ISO-2022-CN-EXT may be affected by GLIBC-SA-2024-0004/CVE-2024-2961.