Vulnerability in Glibc exploited via PHP scripts

A vulnerability (CVE-2024-2961) has been found in the standard C library Glibc, leading to a buffer overflow when converting specially formatted strings in the ISO-2022-CN-EXT encoding using the iconv() function. The researcher who discovered the issue is scheduled to present at the OffensiveCon conference on May 10, with an announcement mentioning the potential exploitation of this vulnerability through applications written in PHP. It has been stated that the problem affects the entire PHP ecosystem and certain applications.

When converting strings in the UCS4 encoding, in accordance with RFC 1922 requirements, the library adds certain escape characters that highlight parts of the string where the encoding has been changed. The vulnerability is caused by insufficient boundary checking of internal buffers by the iconv() function, which can lead to a buffer overflow of up to 4 bytes. Specific fixed values such as ‘$+I’, ‘$+J’, ‘$+K’, ‘$+L’, ‘$+M’, and ‘$*H’ can be written beyond the buffer boundary. Although the exploitation of such a vulnerability for code execution seems unlikely, according to the researcher, this was enough to prepare several exploit prototypes for remote attacks on PHP applications, leading to code execution.

The vulnerability has been present since the year 2000 and has been fixed in the ongoing development branch of Glibc 2.40. The patch is also available for Glibc releases from 2.32 to 2.39. To track the vulnerability fix in distributions, you can check the pages for: Debian, Ubuntu, Gentoo, RHEL, SUSE, Fedora, Arch.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster