Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 8: 2021-0123 Moderate: Glib2 Integer Truncation Security Fix

mageia
Calendar Grey March 11, 2021
Dist Mageia Esm H88
Mageia 8's glibc2.0 update resolves integer saturation and overflow vulnerabilities, while also improving GIO security within setuid operations.
* Fix various instances within GLib where `g_memdup()` was vulnerable to a silent integer truncation and heap overflow problem (discovered by Kevin Backhouse, work by Philip Withna...

Summary

* Fix various instances within GLib where `g_memdup()` was vulnerable to a silent integer truncation and heap overflow problem (discovered by Kevin Backhouse, work by Philip Withnall) (#2319) * Fix some issues with handling over-long (invalid) input when parsing for

References

- https://bugs.mageia.org/show_bug.cgi?id=28392

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/RKZC2OMFCXQTQDGIDS4JBWOWNQUAAOV2/

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/F3TX2KSXDNFQN6HBKCYRZSZWKF4W5EYJ/

Resolution

SRPMS

- 8/core/glib2.0-2.66.7-1.mga8

- 8/core/mingw-glib2-2.66.7-1.mga8

Publication date: 12 Mar 2021
URL: https://advisories.mageia.org/MGASA-2021-0123.html
Type: security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here