CVE-2024-2961 is a high-severity buffer overflow vulnerability in the GNU C Library's iconv() function (versions 2.39 and older) when converting to the ISO-2022-CN-EXT character set, affecting products from Debian, GNU, and NetApp. This flaw allows an attacker to cause an application crash or overwrite adjacent memory, with a CVSS score of 7.3 (High) and an extremely high EPSS score of 0.92156, indicating a significant likelihood of exploitation. It is actively being exploited in the wild, notably as part of the "CosmicSting" attack chain targeting Adobe Commerce and Magento installations, leading to thousands of compromised online stores. A Metasploit module exists, combining this vulnerability with CVE-2024-34102, and it has garnered substantial community discussion and media coverage due to its active use in real-world attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.1.93, < 2.40CPE matchmatch criteria | cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:hci_h300s_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:hci_h500s_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.0 SP 9 Security Updates
Jun 17, 2024HP ThinPro 8.0 SP 9 Security Updates
Jun 17, 2024glibc: Out of bounds write in iconv may lead to remote code execution
Apr 17, 2024The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
Apr 9, 2024