* bsc#1220059 Cross-References: * CVE-2020-36774 . # Security update for glade Announcement ID: SUSE-SU-2024:0983-1 Rating: moderate References: * bsc#1220059 Cross-References: * CVE-2020-36774 CVSS scores: * CVE-2020-36774 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for glade fixes the following issues: * CVE-2020-36774: Fixed crash when rebuilding GladeGtkBox (bsc#1220059). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-983=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * libgladeui-2-devel-3.20.0-7.3.1 * typelib-1_0-Gladeui-2_0-3.20.0-7.3.1 * libgladeui-2-6-debuginfo-3.20.0-7.3.1 * glade-3.20.0-7.3.1 * glade-debugsource-3.20.0-7.3.1 * libgladeui-2-6-3.20.0-7.3.1 * glade-debuginfo-3.20.0-7.3.1 * SUSE Linux Enterprise Software Development Kit 12 SP5 (noarch) * glade-lang-3.20.0-7.3.1 ## References: * https://www.suse.com/security/cve/CVE-2020-36774.html * https://bugzilla.suse.com/show_bug.cgi?id=1220059 . SUSE Security Patch for Gnome tackles a moderate threat level vulnerability. Apply immediately to reduce possible hazards.. SUSE Security Update, Glade Software, Moderate Issue, Security Patch. . LinuxSecurity.com Team
A vulnerability has been discovered in Glade which can lead to a denial of service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202402-27 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Glade: Denial of Service Date: February 19, 2024 Bugs: #747451 ID: 202402-27 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in Glade which can lead to a denial of service. Background ========== Glade is a RAD tool to enable quick & easy development of user interfaces for the GTK+ toolkit (Version 3 only) and the GNOME desktop environment. Affected packages ================= Package Vulnerable Unaffected -------------- ------------ ------------ dev-util/glade < 3.38.2 > = 3.38.2 Description =========== A vulnerability has been found in Glade which can lead to a denial of service when working with specific glade files. Impact ====== A crafted file may lead to crashes in Glade. Workaround ========== There is no known workaround at this time. Resolution ========== All Glade users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-util/glade-3.38.2" References ========== [ 1 ] CVE-2020-36774 https://nvd.nist.gov/vuln/detail/CVE-2020-36774 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202402-27 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.