All errata/sisyphus_e2k/ALT-PU-2024-4585-1
ALT-PU-2024-4585-1

Package update glib2 in branch sisyphus_e2k

Version2.80.0-alt2
Task#0
Published2024-03-27
Max severityHIGH
Severity:

Closed issues (8)

BDU:2023-07646
HIGH7.5

Уязвимость функции is_normal() библиотеки Glib, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2023-11-11Modified: 2026-04-20
CVSS 3.xHIGH 7.5
CVSS:3.x/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.0HIGH 7.8
CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:N/A:C
References
BDU:2023-07650
MEDIUM5.5

Уязвимость функции g_variant_byteswap() библиотеки Glib, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2023-11-11Modified: 2026-04-20
CVSS 3.xMEDIUM 5.5
CVSS:3.x/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.0MEDIUM 4.9
CVSS:2.0/AV:L/AC:L/Au:N/C:N/I:N/A:C
References
BDU:2023-07655
MEDIUM5.5

Уязвимость библиотеки Glib, связанная с восстановлением в памяти недостоверных данных, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2023-11-11Modified: 2026-04-20
CVSS 3.xMEDIUM 5.5
CVSS:3.x/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.0MEDIUM 4.9
CVSS:2.0/AV:L/AC:L/Au:N/C:N/I:N/A:C
References
CVE-2023-32636
HIGH7.5

A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.

Published: 2023-09-14Modified: 2024-11-21
CVSS 3.xHIGH 7.5
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVE-2023-32643
HIGH7.8

A flaw was found in GLib. The GVariant deserialization code is vulnerable to a heap buffer overflow introduced by the fix for CVE-2023-32665. This bug does not affect any released version of GLib, but does affect GLib distributors who followed the guidance of GLib developers to backport the initial fix for CVE-2023-32665.

Published: 2023-09-14Modified: 2024-11-21
CVSS 3.xHIGH 7.8
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Closed bugs (1)

/etc/profile.d/glib2.sh неправильно обрабатывает отсутствие /usr/bin/natspec