Back to search
CVE-2024-2961
Published: Apr 17, 2024
Modified: May 12, 2026
PUBLISHED
Description
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
| Vendor | Product | Versions |
|---|---|---|
The GNU C Library | glibc | affected 2.1.93 - < 2.40 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now