Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Mageia 6 MGASA-2018-0405 Moderate: Glib2.0 Null Pointer Issue

mageia
Calendar Grey October 19, 2018
Dist Mageia Esm H88
Enhanced glib2.0 versions fix vulnerabilities in Mageia 6, tackling NULL dereference and buffer overflow concerns.
The updated glib2.0 packages fix security vulnerabilities: In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference (CVE-2018-16428)

Summary

The updated glib2.0 packages fix security vulnerabilities:
In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference (CVE-2018-16428).
GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str() (CVE-2018-16429).

References

- https://bugs.mageia.org/show_bug.cgi?id=23665

- https://ubuntu.com/security/notices/USN-3767-1

- https://www.cve.org/CVERecord?id=CVE-2018-16428

- https://www.cve.org/CVERecord?id=CVE-2018-16429

Resolution

SRPMS

- 6/core/glib2.0-2.54.3-1.2.mga6

Publication date: 19 Oct 2018
URL: https://advisories.mageia.org/MGASA-2018-0405.html
Type: security
CVE: CVE-2018-16428, CVE-2018-16429

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here