oerdnj / deb.sury.org

Public bugreports for anything ppa:ondrej/*
800 stars 26 forks source link

GLIBC-SA-2024-0004/CVE-2024-2961: ISO-2022-CN-EXT: fix out-of-bound writes when writing escape sequence #2121

Open oerdnj opened 2 months ago

oerdnj commented 2 months ago

Just a quick summary:

On older Debian, edit /usr/lib/x86_64-linux-gnu/gconv/gconv-modules.d/gconv-modules-extra.conf, comment out vulnerable locale and reload the iconv cache. Here's Rocky Linux guide that should be applicable (with just different paths) to Debian and Ubuntu: https://rockylinux.org/news/glibc-vulnerability-april-2024/

sleemanj commented 2 months ago

Instructions for manually disabling on older systems generally....

https://old.reddit.com/r/PHP/comments/1c9lslg/security_vulnerability_in_php_caused_by_glibc/l0o6zi1/

oerdnj commented 2 months ago

@sleemanj That's what the link to Rocky Linux contains. The Reddit connect looks copied from that page…

oerdnj commented 1 month ago

Here's an update from PHP itself: https://www.php.net/archive/2024.php#2024-04-24-1