← volver
CVE-2024-2961highexplotación observadaCWE-787

CVE-2024-2961

100Vexday Risk Score

Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.

ssvc Actcvss 7.3epss 88%
de la publicación al arma40 días
Publicada en NVD17 abr
1ª PoC+40d
metasploit+100d
VulnCheck+152d
probabilidad de explotación
88%top 1% de las CVE
explotación observada
síVulnCheck
11 exploit(s) público(s)
Lo que declaran los fabricantes (VEX)

Declaraciones oficiales de los fabricantes en formato CSAF/VEX: si su producto está afectado, ya corregido o descartado — y por qué. Es afirmación del fabricante, no juicio de Vexday.

Afectado
2 productos (10 componentes)
Red Hat Enterprise Linux 6 · Red Hat OpenShift Container Platform 4
workaround: This issue can be mitigated by removing the ISO-2022-CN-EXT from glibc-gconv-extra's modules configuration. This can be done by: 1) Verify if the module is loaded by running: ~~~ $ iconv -l | grep -E 'CN-?EXT' ISO-2022-CN-EXT// ISO2022CNEXT// ~~~…
Corregido
41 productos (8334 componentes)
Red Hat Enterprise Linux BaseOS (v. 8) · Red Hat Enterprise Linux BaseOS EUS (v.8.8) · Red Hat Enterprise Linux BaseOS EUS (v.8.6) · Red Hat Enterprise Linux BaseOS (v. 9) · Red Hat Enterprise Linux BaseOS EUS (v.9.0) · y otros 36
No afectado
8 productos (2994 componentes) — porque el código vulnerable no está presente en el producto
Red Hat OpenShift Container Platform 4.14 · Red Hat OpenShift Container Platform 4.16 · Red Hat OpenShift Container Platform 4.13 · Red Hat OpenShift Container Platform 4.15 · Red Hat OpenShift Container Platform 4.12 · y otros 3
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Productos afectados
The GNU C Library · glibc
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.