Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Mageia: 2021-0318 Moderate Risk of GLib Buffer Overflow Vulnerability

mageia
Calendar Grey July 8, 2021
Dist Mageia Esm H88
A crucial security patch for GLib in Mageia addresses issues related to buffer overflow and potential denial of service threats. Stay informed about the latest vulnerabilities.
Krzesimir Nowak discovered that GLib incorrectly handled certain large buffers

Summary

Krzesimir Nowak discovered that GLib incorrectly handled certain large buffers. A remote attacker could use this issue to cause applications linked to GLib to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2021-27218).
Kevin Backhouse discovered that GLib incorrectly handled certain memory allocations. A remote attacker could use this issue to cause applications linked to GLib to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2021-27219).
It was discovered that GLib incorrectly handled certain symlinks when replacing files. If a user or automated system were tricked into extracting a specially crafted file with File Roller, a remote attacker could possibly create files outside of the intended directory (CVE-2021-28153).

References

- https://bugs.mageia.org/show_bug.cgi?id=28520

- https://ubuntu.com/security/notices/USN-4759-1

- https://ubuntu.com/security/notices/USN-4764-1

- https://www.cve.org/CVERecord?id=CVE-2021-27218

- https://www.cve.org/CVERecord?id=CVE-2021-27219

- https://www.cve.org/CVERecord?id=CVE-2021-28153

Resolution

SRPMS

- 7/core/glib2.0-2.60.2-1.5.mga7

Publication date: 08 Jul 2021
URL: https://advisories.mageia.org/MGASA-2021-0318.html
Type: security
CVE: CVE-2021-27218, CVE-2021-27219, CVE-2021-28153

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here