-
Notifications
You must be signed in to change notification settings - Fork 43
Closed
flatcar/scripts
#2614Labels
advisorysecurity advisorysecurity advisorycvss/CRITICAL>= 9 assessed CVSS>= 9 assessed CVSSsecuritysecurity concernssecurity concerns
Description
Name: glib
CVEs: CVE-2024-52533
CVSSs: 9.8
Action Needed: update to >= 2.82.1
Summary: gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.
See also https://seclists.org/oss-sec/2024/q4/90, https://bugzilla.redhat.com/show_bug.cgi?id=2325340.
refmap.gentoo: TBD
Metadata
Metadata
Assignees
Labels
advisorysecurity advisorysecurity advisorycvss/CRITICAL>= 9 assessed CVSS>= 9 assessed CVSSsecuritysecurity concernssecurity concerns
Type
Projects
Status
Implemented