GNOME GLib before 2.65.3 has an integer overflow, that might lead to an out-of-bounds write, in g_option_group_add_entries. NOTE: the vendor's position is "Realistically this is not a security issue. The standard pattern is for callers to provide a static list of option entries in a fixed number of calls to g_option_group_add_entries()." The researcher states that this pattern is undocumented
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade glib | Mar 21, 2024 | Dec 14, 2020 |
| Amazon Linux Ami 2 | — | Upgrade glib2Upgrade glib2-docUpgrade glib2-develUpgrade glib2-debuginfoUpgrade glib2-staticUpgrade glib2-famUpgrade glib2-tests | Apr 19, 2024 | Dec 14, 2020 |
| Amazon_linux | — | Upgrade glib2 | Apr 17, 2024 | Dec 14, 2020 |
| Debian | — | Upgrade glib2.0 | Jul 30, 2024 | Dec 14, 2020 |
| Huawei Euleros 2_0_sp2 | — | Upgrade glib2Upgrade glib2-devel | Sep 16, 2021 | Dec 14, 2020 |
| Huawei Euleros 2_0_sp3 | — | Upgrade glib2Upgrade glib2-devel | Oct 26, 2021 | Dec 14, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade glib2Upgrade glib2-devel | Sep 7, 2021 | Dec 14, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade glib2-develUpgrade glib2Upgrade glib2-fam | Feb 2, 2021 | Dec 14, 2020 |
| Huawei Euleros 2_0_sp9 | — | Upgrade glib2 | Jan 5, 2021 | Dec 14, 2020 |
| Oracle Solaris | — | Upgrade library/glib2 to version 2.66.7-11.4.32.0.1.88.2 on Solaris 11.4Upgrade library/libmozjs-60 to version 60.8.0-11.4.32.0.1.88.2 on Solaris 11.4 | Apr 21, 2021 | Dec 14, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 14, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub