PT-2009-6742 · Gnome+1 · Libglib-2 0-0+8

Diego Petteno

·

Published

1970-01-01

·

Updated

2023-02-13

·

CVE-2008-4316

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GLib versions prior to 2.20 glib2-devel versions prior to 2.12.3 glib2-debuginfo versions prior to 2.12.3 libgio-2 0-0 versions prior to 2.20 libgmodule-2 0-0 versions prior to 2.20 libgobject-2 0-0 versions prior to 2.20 libgthread-2 0-0 versions prior to 2.20 libglib-2 0-0 versions prior to 2.20
Description The issue is related to multiple integer overflows in the glib/gbase64.c file of GLib, which can be exploited by context-dependent attackers to execute arbitrary code via a long string that is converted either from or to a base64 representation. The vulnerability can lead to a disruption of confidentiality, integrity, and availability of protected information. It can be exploited locally.
Recommendations For GLib versions prior to 2.20, update to version 2.20 or later. For glib2-devel versions prior to 2.12.3, update to version 2.12.3 or later. For glib2-debuginfo versions prior to 2.12.3, update to version 2.12.3 or later. For libgio-2 0-0 versions prior to 2.20, update to version 2.20 or later. For libgmodule-2 0-0 versions prior to 2.20, update to version 2.20 or later. For libgobject-2 0-0 versions prior to 2.20, update to version 2.20 or later. For libgthread-2 0-0 versions prior to 2.20, update to version 2.20 or later. For libglib-2 0-0 versions prior to 2.20, update to version 2.20 or later. As a temporary workaround, consider disabling the base64 conversion functions until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04402
BDU:2015-04403
BDU:2015-04404
BDU:2015-04405
BDU:2015-04406
BDU:2015-04407
BDU:2015-04408
BDU:2015-04409
BDU:2015-04410
BDU:2015-04411
BDU:2015-04412
BDU:2015-04413
BDU:2015-04414
BDU:2015-04415
BDU:2015-04416
BDU:2015-04417
BDU:2015-04418
BDU:2015-04419
BDU:2015-04420
BDU:2015-04421
BDU:2015-04422
BDU:2015-04423
BDU:2015-04424
BDU:2015-04425
BDU:2015-04426
BDU:2015-05105
BDU:2015-05106
BDU:2015-05107
BDU:2015-05108
BDU:2015-05109
BDU:2015-05110
BDU:2015-05111
BDU:2015-05112
BDU:2015-05113
BDU:2015-05114
BDU:2015-05115
BDU:2015-05116
BDU:2015-05117
BDU:2015-05118
BDU:2015-05119
BDU:2015-05120
BDU:2015-05121
BDU:2015-05122
BDU:2015-05123
BDU:2015-05124
BDU:2015-05125
BDU:2015-05126
BDU:2015-05127
BDU:2015-05128
BDU:2015-05129
BDU:2015-05130
BDU:2015-05131
BDU:2015-05132
BDU:2015-05133
BDU:2015-05134
BDU:2015-05135
BDU:2015-05136
BDU:2015-05137
BDU:2015-05138
BDU:2015-05139
BDU:2015-06763
BDU:2015-06764
BDU:2015-09359
CVE-2008-4316
DSA-1747-1
OPENSUSE-SU-2024:10473-1
RHSA-2009:0336
RHSA-2009_0336

Affected Products

Glib
Red Hat
Glib2-Debuginfo
Glib2-Devel
Libgio-2 0-0
Libglib-2 0-0
Libgmodule-2 0-0
Libgobject-2 0-0
Libgthread-2 0-0