Out-of-bounds Write Affecting glibc-langpack-sk package, versions <0:2.26-64.amzn2.0.1
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-AMZN2-GLIBCLANGPACKSK-6745049
- published 1 May 2024
- disclosed 17 Apr 2024
Introduced: 17 Apr 2024
CVE-2024-2961 Open this link in a new tabHow to fix?
Upgrade Amazon-Linux:2 glibc-langpack-sk to version 0:2.26-64.amzn2.0.1 or higher.
This issue was patched in ALAS2-2024-2521.
NVD Description
Note: Versions mentioned in the description apply only to the upstream glibc-langpack-sk package and not the glibc-langpack-sk package as distributed by Amazon-Linux.
See How to fix? for Amazon-Linux:2 relevant fixed versions and status.
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
References
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2961
- https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0004
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P3I4KYS6EU6S7QZ47WFNTPVAHFIUQNEL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YAMJQI3Y6BHWV3CUTYBXOZONCUJNOB2Z/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BTJFBGHDYG5PEIFD5WSSSKSFZ2AZWC5N/
- http://www.openwall.com/lists/oss-security/2024/04/24/2
- http://www.openwall.com/lists/oss-security/2024/04/17/9
- http://www.openwall.com/lists/oss-security/2024/04/18/4
- https://lists.debian.org/debian-lts-announce/2024/05/msg00001.html
- http://www.openwall.com/lists/oss-security/2024/05/27/1
- http://www.openwall.com/lists/oss-security/2024/05/27/2
- http://www.openwall.com/lists/oss-security/2024/05/27/6
- http://www.openwall.com/lists/oss-security/2024/05/27/3
- http://www.openwall.com/lists/oss-security/2024/05/27/4
- http://www.openwall.com/lists/oss-security/2024/05/27/5
- https://security.netapp.com/advisory/ntap-20240531-0002/
- http://www.openwall.com/lists/oss-security/2024/07/22/5
- https://github.com/ambionics/cnext-exploits