Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

Scientific Linux 5.x: CVE-2008-4316 Moderate: glib2 Buffer Overflow

Scientific Large Esm H446
Moderate: glib2 security update
Date: Tue, 24 Mar 2009 16:09:36 -0500
Reply-To: Troy Dawson 
Sender: Security Errata for Scientific Linux
 
From: Troy Dawson 
Subject: Security ERRATA Moderate: glib2 on SL5.x i386/x86_64
Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it."
 

Synopsis: Moderate: glib2 security update
Issue date: 2009-03-24
CVE Names: CVE-2008-4316

Diego Petten discovered multiple integer overflows causing heap-based
buffer overflows in GLib's Base64 encoding and decoding functions. An
attacker could use these flaws to crash an application using GLib's
Base64 functions to encode or decode large, untrusted inputs, or,
possibly, execute arbitrary code as the user running the application.
(CVE-2008-4316)

SL 5.x

 SRPMS:
glib2-2.12.3-4.el5_3.1.src.rpm
 i386:
glib2-2.12.3-4.el5_3.1.i386.rpm
glib2-devel-2.12.3-4.el5_3.1.i386.rpm
 x86_64:
glib2-2.12.3-4.el5_3.1.i386.rpm
glib2-2.12.3-4.el5_3.1.x86_64.rpm
glib2-devel-2.12.3-4.el5_3.1.i386.rpm
glib2-devel-2.12.3-4.el5_3.1.x86_64.rpm

-Connie Sieh
-Troy Dawson