Make Homepage | Add To Favorites | Print Page | Submit News | Feedback | Contact | 

Your Technical Computer Information Resource!  
     

  Technical Updates @ TACKtech Corp.  

04.24.2024 - Statement on glibc/iconv Vulnerability



View PHP related news. Recently, a bug in glibc version 2.39 and older (CVE-2024-2961) was uncovered where a buffer overflow in character set conversions to the ISO-2022-CN-EXT character set can result in remote code execution. This specific buffer overflow in glibc is exploitable through PHP, which uses the iconv functionality in glibc to do character set conversions. Although the bug is exploitable in the context of the PHP Engine, the bug is not in PHP. It is also not directly exploitable remotely.There are numerous reports online with titles like "Mitigating the iconv Vulnerability for PHP (CVE-2024-2961)" or "PHP Under Attack". These titles are misleading as this is not a bug in PHP itself.Currently there is no fix for this issue, but there is a workaround described in GLIBC Vulnerability on Servers Serving PHP. It explains a way how to remove the problematic character set from glibc. Perform this procedure for every gconv-modules-extra.conf file that is available on your system.Additionally it is also good practice for applications to accept only specific charsets, with an allow-list.Some Linux distributions such as Debian, CentOS, and others, already have published patched variants of glibc. Please upgrade as soon as possible.Once an update is available in glibc, updating that package on your Linux machine will be enough to alleviate the issue. You do not need to update PHP, as glibc is a dynamically linked library.PHP users on Windows are not affected.There will therefore also not be a new version of PHP for this vulnerability.

- Download PHP
- View Press Release
- Visit PHP Group

NID: 96130 / Submitted by: The Zilla of Zuron
Categories: Open Source, Server Applications, Programming
Most recent PHP related news.
PHP 8.4.0 RC2 available for testing
PHP 8.4.0 RC 1 now available for testing
PHP 8.4.0 Beta 5 available for testing
PHP 8.4.0 Beta 4 now available for testing
PHP 8.4.0 Beta 3 now available for testing
View archive of PHP related news.
  Popular Tech News  
  Most Viewed News  
  Top Affiliates  
.....