Out-of-bounds Write Affecting glibc package, versions [2.32,2.32-140) [2.33,2.33-263) [2.34,2.34-459) [2.35,2.35-315) [2.36,2.36-164) [2.37,2.37-89) [2.38,2.38-66) [.2.39,2.39-31)


0.0
high

Snyk CVSS

    Attack Complexity Low
    Integrity High
    Availability High

    Threat Intelligence

    EPSS 0.04% (13th percentile)
Expand this section
SUSE
8.2 high
Expand this section
Red Hat
8.8 high

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-UNMANAGED-GLIBC-6669950
  • published 21 Apr 2024
  • disclosed 17 Apr 2024
  • credit Charles Fol

How to fix?

Upgrade glibc to version 2.32-140, 2.33-263, 2.34-459, 2.35-315, 2.36-164, 2.37-89, 2.38-66, 2.39-31 or higher.

Overview

Affected versions of this package are vulnerable to Out-of-bounds Write through the iconv function. An attacker can crash an application or overwrite a neighbouring variable by converting strings to the ISO-2022-CN-EXT character set.