Advisories ยป MGASA-2024-0147

Updated glibc packages fix security vulnerabilitiy

Publication date: 25 Apr 2024
Modification date: 25 Apr 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-2961

Description

The iconv() function in the GNU C Library versions 2.39 and older may
overflow the output buffer passed to it by up to 4 bytes when converting
strings to the ISO-2022-CN-EXT character set, which may be used to crash
an application or overwrite a neighbouring variable. (CVE-2024-2961)
                

References

SRPMS

9/core