Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 8: DLA-1866-1 Urgent: Security Update for GLib2.0 Released

debian lts
Calendar Grey July 31, 2019
Dist Debian Esm H88
Debian LTS addresses GLib 2.0 vulnerabilities; patches for memory corruption and NULL reference issues are included.
Various minor issues have been addressed in the GLib library

Summary

CVE-2018-16428

In GNOME GLib, g_markup_parse_context_end_parse() in gmarkup.c
had a NULL pointer dereference.

CVE-2018-16429

GNOME GLib had an out-of-bounds read vulnerability in
g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().

CVE-2019-13012

The keyfile settings backend in GNOME GLib (aka glib2.0) before
created directories using g_file_make_directory_with_parents
(kfsb->dir, NULL, NULL) and files using g_file_replace_contents
(kfsb->file, contents, length, NULL, FALSE,
G_FILE_CREATE_REPLACE_DESTINATION, NULL, NULL, NULL). Consequently,
it did not properly restrict directory (and file) permissions.
Instead, for directories, 0777 permissions were used; for files,
default file permissions were used. This issue is similar to
CVE-2019-12450.

For Debian 8 "Jessie", these problems have been fixed in version
2.42.1-1+deb8u2.

We recommend that you upgrade your glib2.0 packages.

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

<pre><font face="Courier">Package: glib2.0
Version: 2.42.1-1+deb8u2
CVE ID: CVE-2018-16428 CVE-2018-16429 CVE-2019-13012
Debian Bug: 931234

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here