An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having . MGASA-2024-0311 - Updated glib2.0 packages fix security vulnerability Publication date: 25 Sep 2024 URL: https://advisories.mageia.org/MGASA-2024-0311.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-34397 An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact. (CVE-2024-34397) References: - https://bugs.mageia.org/show_bug.cgi?id=33198 - https://www.openwall.com/lists/oss-security/2024/05/07/5 - https://ubuntu.com/security/notices/USN-6768-1 - - https://www.cve.org/CVERecord?id=CVE-2024-34397 SRPMS: - 9/core/glib2.0-2.76.3-1.2.mga9 . Revised glib2.0 versions from Mageia resolve a critical vulnerability related to D-Bus signal impersonation.. glib2.0 updates, Mageia security advisory, GNOME security issues. . LinuxSecurity.com Team
* bsc#1224044 Cross-References: * CVE-2024-34397 . # Security update for glib2 Announcement ID: SUSE-SU-2024:1830-2 Rating: low References: * bsc#1224044 Cross-References: * CVE-2024-34397 CVSS scores: * CVE-2024-34397 ( SUSE ): 3.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Micro 5.5 An update that solves one vulnerability can now be installed. ## Description: This update for glib2 fixes the following issues: * CVE-2024-34397: Fixed signal subscription unicast spoofing vulnerability (bsc#1224044). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-1830=1 ## Package List: * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * glib2-debugsource-2.70.5-150400.3.11.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.11.1 * glib2-tools-debuginfo-2.70.5-150400.3.11.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libglib-2_0-0-2.70.5-150400.3.11.1 * libgio-2_0-0-2.70.5-150400.3.11.1 * libgobject-2_0-0-2.70.5-150400.3.11.1 * libgmodule-2_0-0-2.70.5-150400.3.11.1 * glib2-tools-2.70.5-150400.3.11.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.11.1 ## References: * https://www.suse.com/security/cve/CVE-2024-34397.html * https://bugzilla.suse.com/show_bug.cgi?id=1224044 . Patch notice for glib2 resolves signal forgery concern for SUSE Micro 5.5, classified as low severity.. SUSE Security Advisory, glib2 Update, low Severity Patch. . Severity: Low. LinuxSecurity.com Team
* bsc#1224044 Cross-References: * CVE-2024-34397 . # Security update for glib2 Announcement ID: SUSE-SU-2024:2247-1 Rating: low References: * bsc#1224044 Cross-References: * CVE-2024-34397 CVSS scores: * CVE-2024-34397 ( SUSE ): 3.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 An update that solves one vulnerability can now be installed. ## Description: This update for glib2 fixes the following issues: * CVE-2024-34397: Fixed signal subscription unicast spoofing vulnerability (bsc#1224044). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2024-2247=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-2247=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-2247=1 ## Package List: * SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64) * libglib-2_0-0-debuginfo-2.62.6-150200.3.18.1 * glib2-tools-debuginfo-2.62.6-150200.3.18.1 * libgmodule-2_0-0-2.62.6-150200.3.18.1 * glib2-tools-2.62.6-150200.3.18.1 * libgio-2_0-0-2.62.6-150200.3.18.1 * libgio-2_0-0-debuginfo-2.62.6-150200.3.18.1 * libgmodule-2_0-0-debuginfo-2.62.6-150200.3.18.1 * glib2-debugsource-2.62.6-150200.3.18.1 * libgobject-2_0-0-debuginfo-2.62.6-150200.3.18.1 * libglib-2_0-0-2.62.6-150200.3.18.1 * libgobject-2_0-0-2.62.6-150200.3.18.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * libglib-2_0-0-debuginfo-2.62.6-150200.3.18.1 * glib2-tools-debuginfo-2.62.6-150200.3.18.1 * libgmodule-2_0-0-2.62.6-150200.3.18.1 * glib2-tools-2.62.6-150200.3.18.1 *libgio-2_0-0-2.62.6-150200.3.18.1 * libgio-2_0-0-debuginfo-2.62.6-150200.3.18.1 * libgmodule-2_0-0-debuginfo-2.62.6-150200.3.18.1 * glib2-debugsource-2.62.6-150200.3.18.1 * libgobject-2_0-0-debuginfo-2.62.6-150200.3.18.1 * libglib-2_0-0-2.62.6-150200.3.18.1 * libgobject-2_0-0-2.62.6-150200.3.18.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * libglib-2_0-0-debuginfo-2.62.6-150200.3.18.1 * glib2-tools-debuginfo-2.62.6-150200.3.18.1 * libgmodule-2_0-0-2.62.6-150200.3.18.1 * glib2-tools-2.62.6-150200.3.18.1 * libgio-2_0-0-2.62.6-150200.3.18.1 * libgio-2_0-0-debuginfo-2.62.6-150200.3.18.1 * libgmodule-2_0-0-debuginfo-2.62.6-150200.3.18.1 * glib2-debugsource-2.62.6-150200.3.18.1 * libgobject-2_0-0-debuginfo-2.62.6-150200.3.18.1 * libglib-2_0-0-2.62.6-150200.3.18.1 * libgobject-2_0-0-2.62.6-150200.3.18.1 ## References: * https://www.suse.com/security/cve/CVE-2024-34397.html * https://bugzilla.suse.com/show_bug.cgi?id=1224044 . A security patch for glib2 resolves unicast impersonation vulnerabilities in SUSE Linux Enterprise Micro systems, classified as low risk.. glib2 security patch, SUSE update, signal spoofing, patch instructions. . Severity: Low. LinuxSecurity.com Team
* bsc#1224044 Cross-References: * CVE-2024-34397 . # Security update for glib2 Announcement ID: SUSE-SU-2024:1830-1 Rating: low References: * bsc#1224044 Cross-References: * CVE-2024-34397 CVSS scores: * CVE-2024-34397 ( SUSE ): 3.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N Affected Products: * Basesystem Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * openSUSE Leap Micro 5.3 * openSUSE Leap Micro 5.4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for glib2 fixes the following issues: * CVE-2024-34397: Fixed signal subscription unicast spoofing vulnerability (bsc#1224044). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2024-1830=1 * openSUSE Leap Micro 5.3 zypper in -t patch openSUSE-Leap-Micro-5.3-2024-1830=1 * openSUSE Leap Micro 5.4 zypper in -t patch openSUSE-Leap-Micro-5.4-2024-1830=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-1830=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-1830=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-1830=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-1830=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patchSUSE-SLE-Micro-5.4-2024-1830=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-1830=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-1830=1 ## Package List: * openSUSE Leap 15.4 (noarch) * glib2-lang-2.70.5-150400.3.11.1 * gio-branding-upstream-2.70.5-150400.3.11.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * libgio-2_0-0-2.70.5-150400.3.11.1 * libgobject-2_0-0-2.70.5-150400.3.11.1 * libgmodule-2_0-0-2.70.5-150400.3.11.1 * glib2-tests-devel-2.70.5-150400.3.11.1 * glib2-tools-debuginfo-2.70.5-150400.3.11.1 * glib2-tools-2.70.5-150400.3.11.1 * libglib-2_0-0-2.70.5-150400.3.11.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.11.1 * glib2-devel-debuginfo-2.70.5-150400.3.11.1 * glib2-tests-devel-debuginfo-2.70.5-150400.3.11.1 * libgthread-2_0-0-2.70.5-150400.3.11.1 * libgthread-2_0-0-debuginfo-2.70.5-150400.3.11.1 * glib2-devel-static-2.70.5-150400.3.11.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.11.1 * glib2-devel-2.70.5-150400.3.11.1 * glib2-doc-2.70.5-150400.3.11.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.11.1 * glib2-debugsource-2.70.5-150400.3.11.1 * openSUSE Leap 15.4 (x86_64) * libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.11.1 * libgobject-2_0-0-32bit-2.70.5-150400.3.11.1 * glib2-devel-32bit-2.70.5-150400.3.11.1 * libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.11.1 * libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.11.1 * glib2-tools-32bit-2.70.5-150400.3.11.1 * glib2-devel-32bit-debuginfo-2.70.5-150400.3.11.1 * libgio-2_0-0-32bit-2.70.5-150400.3.11.1 * libgthread-2_0-0-32bit-debuginfo-2.70.5-150400.3.11.1 * glib2-tools-32bit-debuginfo-2.70.5-150400.3.11.1 * libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.11.1 * libglib-2_0-0-32bit-2.70.5-150400.3.11.1 * libgthread-2_0-0-32bit-2.70.5-150400.3.11.1 *libgmodule-2_0-0-32bit-2.70.5-150400.3.11.1 * openSUSE Leap 15.4 (aarch64_ilp32) * glib2-tools-64bit-2.70.5-150400.3.11.1 * libgmodule-2_0-0-64bit-2.70.5-150400.3.11.1 * libgio-2_0-0-64bit-debuginfo-2.70.5-150400.3.11.1 * libgmodule-2_0-0-64bit-debuginfo-2.70.5-150400.3.11.1 * glib2-devel-64bit-debuginfo-2.70.5-150400.3.11.1 * libgobject-2_0-0-64bit-debuginfo-2.70.5-150400.3.11.1 * libgio-2_0-0-64bit-2.70.5-150400.3.11.1 * libglib-2_0-0-64bit-2.70.5-150400.3.11.1 * libgobject-2_0-0-64bit-2.70.5-150400.3.11.1 * libglib-2_0-0-64bit-debuginfo-2.70.5-150400.3.11.1 * libgthread-2_0-0-64bit-debuginfo-2.70.5-150400.3.11.1 * libgthread-2_0-0-64bit-2.70.5-150400.3.11.1 * glib2-devel-64bit-2.70.5-150400.3.11.1 * glib2-tools-64bit-debuginfo-2.70.5-150400.3.11.1 * openSUSE Leap Micro 5.3 (aarch64 x86_64) * libgio-2_0-0-2.70.5-150400.3.11.1 * libgobject-2_0-0-2.70.5-150400.3.11.1 * libgmodule-2_0-0-2.70.5-150400.3.11.1 * glib2-tools-debuginfo-2.70.5-150400.3.11.1 * libglib-2_0-0-2.70.5-150400.3.11.1 * glib2-tools-2.70.5-150400.3.11.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.11.1 * glib2-debugsource-2.70.5-150400.3.11.1 * openSUSE Leap Micro 5.4 (aarch64 s390x x86_64) * libgio-2_0-0-2.70.5-150400.3.11.1 * libgobject-2_0-0-2.70.5-150400.3.11.1 * libgmodule-2_0-0-2.70.5-150400.3.11.1 * glib2-tools-debuginfo-2.70.5-150400.3.11.1 * libglib-2_0-0-2.70.5-150400.3.11.1 * glib2-tools-2.70.5-150400.3.11.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.11.1 * glib2-debugsource-2.70.5-150400.3.11.1 * openSUSE Leap 15.5 (noarch) * glib2-lang-2.70.5-150400.3.11.1 *gio-branding-upstream-2.70.5-150400.3.11.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * libgio-2_0-0-2.70.5-150400.3.11.1 * libgobject-2_0-0-2.70.5-150400.3.11.1 * libgmodule-2_0-0-2.70.5-150400.3.11.1 * glib2-tests-devel-2.70.5-150400.3.11.1 * glib2-tools-debuginfo-2.70.5-150400.3.11.1 * glib2-tools-2.70.5-150400.3.11.1 * libglib-2_0-0-2.70.5-150400.3.11.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.11.1 * glib2-devel-debuginfo-2.70.5-150400.3.11.1 * glib2-tests-devel-debuginfo-2.70.5-150400.3.11.1 * libgthread-2_0-0-2.70.5-150400.3.11.1 * libgthread-2_0-0-debuginfo-2.70.5-150400.3.11.1 * glib2-devel-static-2.70.5-150400.3.11.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.11.1 * glib2-doc-2.70.5-150400.3.11.1 * glib2-devel-2.70.5-150400.3.11.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.11.1 * glib2-debugsource-2.70.5-150400.3.11.1 * openSUSE Leap 15.5 (x86_64) * libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.11.1 * libgobject-2_0-0-32bit-2.70.5-150400.3.11.1 * glib2-devel-32bit-2.70.5-150400.3.11.1 * libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.11.1 * libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.11.1 * glib2-tools-32bit-2.70.5-150400.3.11.1 * glib2-devel-32bit-debuginfo-2.70.5-150400.3.11.1 * libgio-2_0-0-32bit-2.70.5-150400.3.11.1 * libgthread-2_0-0-32bit-debuginfo-2.70.5-150400.3.11.1 * glib2-tools-32bit-debuginfo-2.70.5-150400.3.11.1 * libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.11.1 * libglib-2_0-0-32bit-2.70.5-150400.3.11.1 * libgthread-2_0-0-32bit-2.70.5-150400.3.11.1 * libgmodule-2_0-0-32bit-2.70.5-150400.3.11.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libgio-2_0-0-2.70.5-150400.3.11.1 * libgobject-2_0-0-2.70.5-150400.3.11.1 * libgmodule-2_0-0-2.70.5-150400.3.11.1 * glib2-tools-debuginfo-2.70.5-150400.3.11.1 * libglib-2_0-0-2.70.5-150400.3.11.1 *glib2-tools-2.70.5-150400.3.11.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.11.1 * glib2-debugsource-2.70.5-150400.3.11.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libgio-2_0-0-2.70.5-150400.3.11.1 * libgobject-2_0-0-2.70.5-150400.3.11.1 * libgmodule-2_0-0-2.70.5-150400.3.11.1 * glib2-tools-debuginfo-2.70.5-150400.3.11.1 * libglib-2_0-0-2.70.5-150400.3.11.1 * glib2-tools-2.70.5-150400.3.11.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.11.1 * glib2-debugsource-2.70.5-150400.3.11.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libgio-2_0-0-2.70.5-150400.3.11.1 * libgobject-2_0-0-2.70.5-150400.3.11.1 * libgmodule-2_0-0-2.70.5-150400.3.11.1 * glib2-tools-debuginfo-2.70.5-150400.3.11.1 * libglib-2_0-0-2.70.5-150400.3.11.1 * glib2-tools-2.70.5-150400.3.11.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.11.1 * glib2-debugsource-2.70.5-150400.3.11.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libgio-2_0-0-2.70.5-150400.3.11.1 * libgobject-2_0-0-2.70.5-150400.3.11.1 * libgmodule-2_0-0-2.70.5-150400.3.11.1 * glib2-tools-debuginfo-2.70.5-150400.3.11.1 * libglib-2_0-0-2.70.5-150400.3.11.1 * glib2-tools-2.70.5-150400.3.11.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.11.1 * glib2-debugsource-2.70.5-150400.3.11.1 * SUSE Linux Enterprise Micro 5.5(aarch64 s390x x86_64) * libgio-2_0-0-2.70.5-150400.3.11.1 * libgobject-2_0-0-2.70.5-150400.3.11.1 * libgmodule-2_0-0-2.70.5-150400.3.11.1 * glib2-tools-debuginfo-2.70.5-150400.3.11.1 * libglib-2_0-0-2.70.5-150400.3.11.1 * glib2-tools-2.70.5-150400.3.11.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.11.1 * glib2-debugsource-2.70.5-150400.3.11.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * libgio-2_0-0-2.70.5-150400.3.11.1 * libgobject-2_0-0-2.70.5-150400.3.11.1 * libgmodule-2_0-0-2.70.5-150400.3.11.1 * glib2-tools-debuginfo-2.70.5-150400.3.11.1 * libglib-2_0-0-2.70.5-150400.3.11.1 * glib2-tools-2.70.5-150400.3.11.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgthread-2_0-0-2.70.5-150400.3.11.1 * glib2-devel-debuginfo-2.70.5-150400.3.11.1 * libgthread-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.11.1 * glib2-devel-2.70.5-150400.3.11.1 * libgio-2_0-0-debuginfo-2.70.5-150400.3.11.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.11.1 * glib2-debugsource-2.70.5-150400.3.11.1 * Basesystem Module 15-SP5 (noarch) * glib2-lang-2.70.5-150400.3.11.1 * Basesystem Module 15-SP5 (x86_64) * libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.11.1 * libgobject-2_0-0-32bit-2.70.5-150400.3.11.1 * libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.11.1 * libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.11.1 * libgio-2_0-0-32bit-2.70.5-150400.3.11.1 * libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.11.1 * libglib-2_0-0-32bit-2.70.5-150400.3.11.1 * libgmodule-2_0-0-32bit-2.70.5-150400.3.11.1 ## References: * https://www.suse.com/security/cve/CVE-2024-34397.html * https://bugzilla.suse.com/show_bug.cgi?id=1224044 . Updates for glib2 security have been released, addressing minor vulnerabilities andenhancing system stability.. openSUSE Security, glib2 Update, SUSE Security Advisory, Linux Patch Management. . Severity: Low. LinuxSecurity.com Team
* bsc#1224044 Cross-References: * CVE-2024-34397 . # Security update for glib2 Announcement ID: SUSE-SU-2024:1833-1 Rating: low References: * bsc#1224044 Cross-References: * CVE-2024-34397 CVSS scores: * CVE-2024-34397 ( SUSE ): 3.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 An update that solves one vulnerability can now be installed. ## Description: This update for glib2 fixes the following issues: * CVE-2024-34397: Fixed signal subscription unicast spoofing vulnerability (bsc#1224044). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-1833=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1833=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1833=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1833=1 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 zypper in -t patch SUSE-SLE-WE-12-SP5-2024-1833=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * libgio-fam-2.48.2-12.37.1 * glib2-debugsource-2.48.2-12.37.1 * glib2-devel-static-2.48.2-12.37.1 * libgio-fam-debuginfo-2.48.2-12.37.1 * glib2-devel-debuginfo-2.48.2-12.37.1 * glib2-devel-2.48.2-12.37.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) *glib2-tools-2.48.2-12.37.1 * libgthread-2_0-0-2.48.2-12.37.1 * glib2-debugsource-2.48.2-12.37.1 * libgio-2_0-0-2.48.2-12.37.1 * libgthread-2_0-0-debuginfo-2.48.2-12.37.1 * libglib-2_0-0-2.48.2-12.37.1 * glib2-tools-debuginfo-2.48.2-12.37.1 * libgobject-2_0-0-debuginfo-2.48.2-12.37.1 * libgmodule-2_0-0-2.48.2-12.37.1 * libgmodule-2_0-0-debuginfo-2.48.2-12.37.1 * libgio-2_0-0-debuginfo-2.48.2-12.37.1 * libglib-2_0-0-debuginfo-2.48.2-12.37.1 * libgobject-2_0-0-2.48.2-12.37.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (noarch) * glib2-lang-2.48.2-12.37.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (x86_64) * libgthread-2_0-0-debuginfo-32bit-2.48.2-12.37.1 * libglib-2_0-0-32bit-2.48.2-12.37.1 * libgio-2_0-0-32bit-2.48.2-12.37.1 * libgobject-2_0-0-debuginfo-32bit-2.48.2-12.37.1 * libglib-2_0-0-debuginfo-32bit-2.48.2-12.37.1 * libgmodule-2_0-0-debuginfo-32bit-2.48.2-12.37.1 * libgio-2_0-0-debuginfo-32bit-2.48.2-12.37.1 * libgmodule-2_0-0-32bit-2.48.2-12.37.1 * libgthread-2_0-0-32bit-2.48.2-12.37.1 * libgobject-2_0-0-32bit-2.48.2-12.37.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * glib2-tools-2.48.2-12.37.1 * libgthread-2_0-0-2.48.2-12.37.1 * glib2-debugsource-2.48.2-12.37.1 * libgio-2_0-0-2.48.2-12.37.1 * libgthread-2_0-0-debuginfo-2.48.2-12.37.1 * libglib-2_0-0-2.48.2-12.37.1 * glib2-tools-debuginfo-2.48.2-12.37.1 * libgobject-2_0-0-debuginfo-2.48.2-12.37.1 * libgmodule-2_0-0-2.48.2-12.37.1 * libgmodule-2_0-0-debuginfo-2.48.2-12.37.1 * libgio-2_0-0-debuginfo-2.48.2-12.37.1 * libglib-2_0-0-debuginfo-2.48.2-12.37.1 * libgobject-2_0-0-2.48.2-12.37.1 * SUSE Linux Enterprise Server 12 SP5 (noarch) * glib2-lang-2.48.2-12.37.1 * SUSE Linux Enterprise Server 12 SP5 (s390x x86_64) * libgthread-2_0-0-debuginfo-32bit-2.48.2-12.37.1 * libglib-2_0-0-32bit-2.48.2-12.37.1 * libgio-2_0-0-32bit-2.48.2-12.37.1 * libgobject-2_0-0-debuginfo-32bit-2.48.2-12.37.1 * libglib-2_0-0-debuginfo-32bit-2.48.2-12.37.1 * libgmodule-2_0-0-debuginfo-32bit-2.48.2-12.37.1 * libgio-2_0-0-debuginfo-32bit-2.48.2-12.37.1 * libgmodule-2_0-0-32bit-2.48.2-12.37.1 * libgthread-2_0-0-32bit-2.48.2-12.37.1 * libgobject-2_0-0-32bit-2.48.2-12.37.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * glib2-tools-2.48.2-12.37.1 * libgthread-2_0-0-2.48.2-12.37.1 * glib2-debugsource-2.48.2-12.37.1 * libgio-2_0-0-2.48.2-12.37.1 * libgthread-2_0-0-debuginfo-2.48.2-12.37.1 * libglib-2_0-0-2.48.2-12.37.1 * glib2-tools-debuginfo-2.48.2-12.37.1 * libgobject-2_0-0-debuginfo-2.48.2-12.37.1 * libgmodule-2_0-0-2.48.2-12.37.1 * libgmodule-2_0-0-debuginfo-2.48.2-12.37.1 * libgio-2_0-0-debuginfo-2.48.2-12.37.1 * libglib-2_0-0-debuginfo-2.48.2-12.37.1 * libgobject-2_0-0-2.48.2-12.37.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (noarch) * glib2-lang-2.48.2-12.37.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (x86_64) * libgthread-2_0-0-debuginfo-32bit-2.48.2-12.37.1 * libglib-2_0-0-32bit-2.48.2-12.37.1 * libgio-2_0-0-32bit-2.48.2-12.37.1 * libgobject-2_0-0-debuginfo-32bit-2.48.2-12.37.1 * libglib-2_0-0-debuginfo-32bit-2.48.2-12.37.1 * libgmodule-2_0-0-debuginfo-32bit-2.48.2-12.37.1 * libgio-2_0-0-debuginfo-32bit-2.48.2-12.37.1 * libgmodule-2_0-0-32bit-2.48.2-12.37.1 * libgthread-2_0-0-32bit-2.48.2-12.37.1 * libgobject-2_0-0-32bit-2.48.2-12.37.1 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 (x86_64) * libgio-fam-2.48.2-12.37.1 * libgio-fam-debuginfo-2.48.2-12.37.1 * glib2-debugsource-2.48.2-12.37.1 ## References: * https://www.suse.com/security/cve/CVE-2024-34397.html * https://bugzilla.suse.com/show_bug.cgi?id=1224044 . Crucial patch released for glib2 fixing a minor but critical signal impersonation vulnerability in SUSE distributions. Take action to ensureyour security!. SUSE glib2 update DoS signal spoofing, security patch, update instructions. . Severity: Low. LinuxSecurity.com Team
Resolve CVE-2024-34397 (GDBus signal subscriptions for well-known names are vulnerable to unicast spoofing), and also update gnome-shell to ensure this fix does not break the screencast feature.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-fd2569c4e9 2024-05-14 03:27:20.127802 -------------------------------------------------------------------------------- Name : glib2 Product : Fedora 39 Version : 2.78.6 Release : 1.fc39 URL : https://www.gtk.org Summary : A library of handy utility functions Description : GLib is the low-level core library that forms the basis for projects such as GTK+ and GNOME. It provides data structure handling for C, portability wrappers, and interfaces for such runtime functionality as an event loop, threads, dynamic loading, and an object system. -------------------------------------------------------------------------------- Update Information: Resolve CVE-2024-34397 (GDBus signal subscriptions for well-known names are vulnerable to unicast spoofing), and also update gnome-shell to ensure this fix does not break the screencast feature. -------------------------------------------------------------------------------- ChangeLog: * Thu May 9 2024 Michael Catanzaro - 2.78.6-1 - Update to 2.78.6 * Tue May 7 2024 Michael Catanzaro - 2.78.5-1 - Update to 2.78.5 * Wed Feb 21 2024 Nieves Montero - 2.78.4-1 - Update to 2.78.4 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2279640 - CVE-2024-34397 glib2: Signal subscription vulnerabilities [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2279640 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-fd2569c4e9' at the command line. For more information, refer to the dnf documentationavailable at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.