------------------------------------------------------------------------- Debian LTS Advisory DLA-3583-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Santiago Ruano Rincón September 25, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : glib2.0 Version : 2.58.3-2+deb10u5 CVE ID : CVE-2023-29499 CVE-2023-32611 CVE-2023-32665 Several security vulnerabilities were found in GLib, a general-purpose utility library, used by projects such as GTK+, GIMP, and GNOME. CVE-2023-29499 GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service. CVE-2023-32611 GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service. CVE-2023-32665 GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processing, leading to denial of service. For Debian 10 buster, these problems have been fixed in version 2.58.3-2+deb10u5. We recommend that you upgrade your glib2.0 packages. For the detailed security status of glib2.0 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/glib2.0 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS