Security
Headlines
HeadlinesLatestCVEs

Headline

Ubuntu Security Notice USN-6165-2

Ubuntu Security Notice 6165-2 - USN-6165-1 fixed vulnerabilities in GLib. This update provides the corresponding updates for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. It was discovered that GLib incorrectly handled non-normal GVariants. An attacker could use this issue to cause GLib to crash, resulting in a denial of service, or perform other unknown attacks.

Packet Storm
#vulnerability#ubuntu#dos
==========================================================================Ubuntu Security Notice USN-6165-2October 19, 2023glib2.0 vulnerabilities==========================================================================A security issue affects these releases of Ubuntu and its derivatives:- Ubuntu 18.04 LTS (Available with Ubuntu Pro)- Ubuntu 16.04 LTS (Available with Ubuntu Pro)- Ubuntu 14.04 LTS (Available with Ubuntu Pro)Summary:Several security issues were fixed in GLib.Software Description:- glib2.0: GLib library of C routinesDetails:USN-6165-1 fixed vulnerabilities in GLib. This update provides thecorresponding updates for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu18.04 LTS.Original advisory details:It was discovered that GLib incorrectly handled non-normal GVariants. Anattacker could use this issue to cause GLib to crash, resulting in adenial of service, or perform other unknown attacks.Update instructions:The problem can be corrected by updating your system to the followingpackage versions:Ubuntu 18.04 LTS (Available with Ubuntu Pro):libglib2.0-0 2.56.4-0ubuntu0.18.04.9+esm3libglib2.0-bin 2.56.4-0ubuntu0.18.04.9+esm3Ubuntu 16.04 LTS (Available with Ubuntu Pro):libglib2.0-0 2.48.2-0ubuntu4.8+esm3libglib2.0-bin 2.48.2-0ubuntu4.8+esm3Ubuntu 14.04 LTS (Available with Ubuntu Pro):libglib2.0-0 2.40.2-0ubuntu1.1+esm6libglib2.0-bin 2.40.2-0ubuntu1.1+esm6In general, a standard system update will make all the necessary changes.References:https://ubuntu.com/security/notices/USN-6165-2https://ubuntu.com/security/notices/USN-6165-1CVE-2023-29499, CVE-2023-32611, CVE-2023-32636, CVE-2023-32643,CVE-2023-32665

Related news

Red Hat Security Advisory 2024-2528-03

Red Hat Security Advisory 2024-2528-03 - An update for mingw-glib2 is now available for Red Hat Enterprise Linux 9.

Gentoo Linux Security Advisory 202311-18

Gentoo Linux Security Advisory 202311-18 - Multiple vulnerabilities have been discovered in GLib. Versions greater than or equal to 2.74.4 are affected.

CVE-2023-32611: cve-details

A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service.

CVE-2023-32636: (CVE-2023-32636) fuzz_variant_text: Timeout in fuzz_variant_text (#2841) · Issues · GNOME / GLib · GitLab

A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.

CVE-2023-32643

A flaw was found in GLib. The GVariant deserialization code is vulnerable to a heap buffer overflow introduced by the fix for CVE-2023-32665. This bug does not affect any released version of GLib, but does affect GLib distributors who followed the guidance of GLib developers to backport the initial fix for CVE-2023-32665.

CVE-2023-32665: Invalid Bug ID

A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processing, leading to denial of service.

CVE-2023-29499: (CVE-2023-29499) GVariant offset table entry size is not checked in is_normal() (#2794) · Issues · GNOME / GLib · GitLab

A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service.

Packet Storm: Latest News

Acronis Cyber Protect/Backup Remote Code Execution