welcomattic, French
@welcomattic@phpc.social avatar

A 24 years old bug has been discovered in iconv in glibc, it impacts PHP engine.

CVE: https://nvd.nist.gov/vuln/detail/CVE-2024-2961
More detail in video: https://www.youtube.com/watch?v=kQdRT2odUIk

wouterj,
@wouterj@phpc.social avatar

@welcomattic this is a bit of misinformation unfortunately. As far as I know, it doesn't affect the PHP engine.

You can be affected by the bug in glibc if you're using the PHP iconv extension though (and enabled ISO-2022-CN-EXT in glibc).

Afaik, glibc is dynamically linked by PHP so what you need is to upgrade glibc to a patched version (which most distributions provide by now).

https://phpc.social/@heiglandreas/112319156714872060

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • kavyap
  • ngwrru68w68
  • Durango
  • DreamBathrooms
  • mdbf
  • magazineikmin
  • thenastyranch
  • Youngstown
  • khanakhh
  • slotface
  • everett
  • vwfavf
  • rosin
  • osvaldo12
  • provamag3
  • GTA5RPClips
  • ethstaker
  • tacticalgear
  • InstantRegret
  • cisconetworking
  • cubers
  • tester
  • anitta
  • modclub
  • Leos
  • normalnudes
  • megavids
  • JUstTest
  • All magazines