CVE-2024-2961
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- March 26, 2024
- Published Date
- April 17, 2024
- Last Updated
- February 13, 2025
- Vendor
- The GNU C Library
- Product
- glibc
- Description
- The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
EPSS Score
- Score
- 92.24% (Percentile: 99.70%) as of 2025-06-12
SSVC Information
- Exploitation
- poc
- Technical Impact
- total
Exploit Status
- Exploited in the Wild
- Yes (2025-06-12 16:33:01 UTC) Source
References
Recent Mentions
Siemens SIMATIC S7-1500 CPU Family
Source: All CISA Advisories • Published: 2025-06-12 12:00:00 UTC
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/magento_xxe_to_glibc_buf_overflow.rb | 2025-04-29 11:01:13 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
suce0155/CVE-2024-2961_buddyforms_2.7.7
Type: github • Created: 2025-02-04 13:34:33 UTC • Stars: 4
kyotozx/CVE-2024-2961-Remote-File-Read
Type: github • Created: 2025-01-27 03:06:37 UTC • Stars: 4
kjdfklha/CVE-2024-2961_poc
Type: github • Created: 2024-06-04 09:57:46 UTC • Stars: 2
rvizx/CVE-2024-2961
Type: github • Created: 2024-05-20 06:53:23 UTC • Stars: 5
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Detected by Metasploit