icon

🚨 Statement on glibc/iconv Vulnerability

Recently, a bug in glibc version 2.39 and older (CVE-2024-2961) was uncovered where a buffer overflow in character set conversions to the ISO-2022-CN-EXT character set affects PHP.

This specific buffer overflow in glibc is exploitable through PHP, which uses the iconv functionality in glibc to do character set conversions, but not remotely.

🔗 Please read our full statement at php.net/archive/2024.php#2024-