ALL PHP Vulnerable to Glib-C Exploit - CVE-2024-2961 - Please Update Immediately

in #lifelast month

The LAMP stack turns out to have an ancient bug that was thought to be harmless, but turns out to enable system takeover. The Web runs on Linux, and PHP is what most websites are written in today, so this vulnerability that enables a buffer overflow when translating character sets, specifically CN, or certain characters of the CN character set, basically renders every web server 'All your base are belong to us.'

Openwall.com has more and specific information, but MentalOutlaw states that an upcoming conference in May will likely provide a fuller explanation.

There is said to be a hotfix available, so please update without delay.

CVE20242961.png
IMG source - OpenWall.com

Sort:  

The LAMP stack turns out to have an ancient bug that was thought to be harmless, but turns out to enable system takeover. The Web runs on Linux, and PHP is what most websites are written in today, so this vulnerability that enables a buffer overflow when translating character sets, specifically CN, or certain characters of the CN character set, basically renders every web server 'All your base are belong to us.'

Dear @valued-customer !
I understood that you were talking about a situation where personal information is leaked through hacking on the Internet.

There is said to be a hotfix available, so please update without delay.

I didn't understand your argument since I'm using Brave.

Thank you for article!

You have misunderstood. Web servers use PHP programs to provide websites, and they are vulnerable to this bug. Brave is your browser that enables you to access the internet, the websites web servers provide, not your OS, the operating system for your computer when you are not online. You don't run PHP programs on your computer, unless you are serving websites on the internet.

This bug doesn't attack your computer and reveal private information. It takes over internet web site servers that you might visit on the internet, which makes them potentially hazardous to ordinary users like us. Hacked web sites might reveal our private information. The simple way to prevent this is to never give websites your private information. If they don't get it from you, they can't leak it when they're hacked.

You probably aren't vulnerable to this attack because you don't use PHP programs. Still, you should update your computer regularly, and make sure your system has the latest security patches.

Thanks!

You have misunderstood. Web servers use PHP programs to provide websites, and they are vulnerable to this bug. Brave is your browser that enables you to access the internet, the websites web servers provide, not your OS, the operating system for your computer when you are not online. You don't run PHP programs on your computer, unless you are serving websites on the internet.

Dear my respected senior @valued-customer !

Thank you for kind answer!
By the way, I don't know about PHP programs.
I hope you first understand that I am as clueless as an American elementary school student.😂

From your point of view, I am like a barbarian who does not know civilization.
I'm sorry I always disappoint you!😆

I hope your health and long life!