Vulnerability Details CVE-2024-2961
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.922
EPSS Ranking 99.7%
CVSS Severity
CVSS v3 Score 7.3
Products affected by CVE-2024-2961
-
cpe:2.3:a:gnu:glibc:2.1.93
-
cpe:2.3:a:gnu:glibc:2.1.94
-
cpe:2.3:a:gnu:glibc:2.1.95
-
cpe:2.3:a:gnu:glibc:2.1.96
-
cpe:2.3:a:gnu:glibc:2.1.97
-
-
cpe:2.3:a:gnu:glibc:2.10.1
-
cpe:2.3:a:gnu:glibc:2.10.2
-
-
cpe:2.3:a:gnu:glibc:2.11.1
-
cpe:2.3:a:gnu:glibc:2.11.2
-
cpe:2.3:a:gnu:glibc:2.11.3
-
-
cpe:2.3:a:gnu:glibc:2.12.0
-
cpe:2.3:a:gnu:glibc:2.12.1
-
cpe:2.3:a:gnu:glibc:2.12.2
-
-
-
cpe:2.3:a:gnu:glibc:2.14.1
-
cpe:2.3:a:gnu:glibc:2.14.9000
-
-
-
cpe:2.3:a:gnu:glibc:2.16.0
-
cpe:2.3:a:gnu:glibc:2.16.90
-
-
cpe:2.3:a:gnu:glibc:2.17.90
-
-
cpe:2.3:a:gnu:glibc:2.18.90
-
-
cpe:2.3:a:gnu:glibc:2.19.90
-
-
cpe:2.3:a:gnu:glibc:2.2.1
-
cpe:2.3:a:gnu:glibc:2.2.2
-
cpe:2.3:a:gnu:glibc:2.2.3
-
cpe:2.3:a:gnu:glibc:2.2.4
-
cpe:2.3:a:gnu:glibc:2.2.5
-
-
cpe:2.3:a:gnu:glibc:2.20.90
-
-
cpe:2.3:a:gnu:glibc:2.21.90
-
-
cpe:2.3:a:gnu:glibc:2.22.90
-
-
cpe:2.3:a:gnu:glibc:2.23.90
-
-
cpe:2.3:a:gnu:glibc:2.24.90
-
-
cpe:2.3:a:gnu:glibc:2.25.90
-
-
cpe:2.3:a:gnu:glibc:2.26.9000
-
-
cpe:2.3:a:gnu:glibc:2.27.9000
-
-
cpe:2.3:a:gnu:glibc:2.28.9000
-
-
cpe:2.3:a:gnu:glibc:2.29.9000
-
-
cpe:2.3:a:gnu:glibc:2.3.1
-
cpe:2.3:a:gnu:glibc:2.3.10
-
cpe:2.3:a:gnu:glibc:2.3.2
-
cpe:2.3:a:gnu:glibc:2.3.3
-
cpe:2.3:a:gnu:glibc:2.3.4
-
cpe:2.3:a:gnu:glibc:2.3.5
-
cpe:2.3:a:gnu:glibc:2.3.6
-
-
cpe:2.3:a:gnu:glibc:2.30.9000
-
-
cpe:2.3:a:gnu:glibc:2.31.9000
-
-
cpe:2.3:a:gnu:glibc:2.32.0
-
cpe:2.3:a:gnu:glibc:2.32.9000
-
-
cpe:2.3:a:gnu:glibc:2.33.9000
-
-
cpe:2.3:a:gnu:glibc:2.34.9000
-
-
cpe:2.3:a:gnu:glibc:2.35.9000
-
-
cpe:2.3:a:gnu:glibc:2.36.113
-
cpe:2.3:a:gnu:glibc:2.36.9000
-
-
cpe:2.3:a:gnu:glibc:2.37.38
-
cpe:2.3:a:gnu:glibc:2.37.9000
-
-
cpe:2.3:a:gnu:glibc:2.38.19
-
cpe:2.3:a:gnu:glibc:2.38.9000
-
-
cpe:2.3:a:gnu:glibc:2.39.9000
-
-
-
cpe:2.3:a:gnu:glibc:2.5.1
-
-
cpe:2.3:a:gnu:glibc:2.6.1
-
-
-
-
cpe:2.3:a:netapp:active_iq_unified_manager:-
-
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-
-
cpe:2.3:h:netapp:hci_compute_node:-
-
cpe:2.3:h:netapp:hci_h300s:-
-
cpe:2.3:h:netapp:hci_h410c:-
-
cpe:2.3:h:netapp:hci_h410s:-
-
cpe:2.3:h:netapp:hci_h500s:-
-
cpe:2.3:h:netapp:hci_h610c:-
-
cpe:2.3:h:netapp:hci_h610s:-
-
cpe:2.3:h:netapp:hci_h615c:-
-
cpe:2.3:h:netapp:hci_h700s:-
-
cpe:2.3:o:debian:debian_linux:10.0
-
cpe:2.3:o:netapp:hci_compute_node:-
-
cpe:2.3:o:netapp:hci_h300s_firmware:-
-
cpe:2.3:o:netapp:hci_h410c_firmware:-
-
cpe:2.3:o:netapp:hci_h410s_firmware:-
-
cpe:2.3:o:netapp:hci_h500s_firmware:-
-
cpe:2.3:o:netapp:hci_h610c_firmware:-
-
cpe:2.3:o:netapp:hci_h610s_firmware:-
-
cpe:2.3:o:netapp:hci_h615c_firmware:-
-
cpe:2.3:o:netapp:hci_h700s_firmware:-