CVE-2024-2961

HIGH EXPLOITED NUCLEI

GNU C Library <2.39 - Buffer Overflow

Title source: llm

Description

The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.

Exploits (16)

nomisec WORKING POC 504 stars
by ambionics · remote
https://github.com/ambionics/cnext-exploits
nomisec WORKING POC 5 stars
by kyotozx · infoleak
https://github.com/kyotozx/CVE-2024-2961-Remote-File-Read
nomisec WORKING POC 5 stars
by rvizx · poc
https://github.com/rvizx/CVE-2024-2961
nomisec WORKING POC 4 stars
by suce0155 · remote
https://github.com/suce0155/CVE-2024-2961_buddyforms_2.7.7
nomisec WORKING POC 2 stars
by kjdfklha · local
https://github.com/kjdfklha/CVE-2024-2961_poc
nomisec WORKING POC 2 stars
by mattaperkins · poc
https://github.com/mattaperkins/FIX-CVE-2024-2961
nomisec WORKING POC 1 stars
by omarelshopky · remote
https://github.com/omarelshopky/exploit_cve-2023-26326_using_cve-2024-2961
nomisec WORKING POC
by Clarissss · poc
https://github.com/Clarissss/osTicketFileReadIntoRCE
nomisec SUSPICIOUS
by scriptSails · poc
https://github.com/scriptSails/glibcs
nomisec WORKING POC
by 4wayhandshake · poc
https://github.com/4wayhandshake/CVE-2024-2961
nomisec SCANNER
by tnishiox · poc
https://github.com/tnishiox/cve-2024-2961
nomisec WORKING POC
by exfil0 · local
https://github.com/exfil0/test_iconv
nomisec WORKING POC
by absolutedesignltd · poc
https://github.com/absolutedesignltd/iconvfix
vulncheck_xdb WORKING POC
remote
https://github.com/mesudmammad1/CVE-2023-26326_Buddyform_exploit
metasploit WORKING POC EXCELLENT
by Sergey Temnikov, Charles Fol, Heyder, jheysel-r7 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/magento_xxe_to_glibc_buf_overflow.rb

Nuclei Templates (1)

PHP - LFR to Remote Code Execution
HIGHby Kim Dongyoung (Kairos-hk),bolkv,n0ming,RoughBoy0723

References (19)

Scores

CVSS v3 7.3
EPSS 0.9192
EPSS Percentile 99.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Details

VulnCheck KEV 2024-09-16
CWE
CWE-787
Status published
Products (14)
debian/debian_linux 10.0
gnu/glibc 2.1.93 - 2.40
netapp/active_iq_unified_manager
netapp/hci_compute_node
netapp/hci_h300s_firmware
netapp/hci_h410c_firmware
netapp/hci_h410s_firmware
netapp/hci_h500s_firmware
netapp/hci_h610c_firmware
netapp/hci_h610s_firmware
... and 4 more
Published Apr 17, 2024
Tracked Since Feb 18, 2026