Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-14087

Опубликовано: 10 дек. 2025
Источник: debian
EPSS Низкий

Описание

A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
glib2.0fixed2.86.3-1package
glib2.0fixed2.84.4-3~deb13u2trixiepackage
glib2.0fixed2.74.6-2+deb12u8bookwormpackage

Примечания

  • https://gitlab.gnome.org/GNOME/glib/-/issues/3834

  • https://gitlab.gnome.org/GNOME/glib/-/merge_requests/4933

  • https://gitlab.gnome.org/GNOME/glib/-/merge_requests/4934

  • Fixed by: https://gitlab.gnome.org/GNOME/glib/-/commit/3e72fe0fbb32c18a66486c4da8bc851f656af287 (2.86.3)

  • Fixed by: https://gitlab.gnome.org/GNOME/glib/-/commit/6fe481cec709ec65b5846113848723bc25a8782a (2.86.3)

  • Fixed by: https://gitlab.gnome.org/GNOME/glib/-/commit/dd333a40aa95819720a01caf6de564cd8a4a6310 (2.86.3)

EPSS

Процентиль: 57%
0.00352
Низкий

Связанные уязвимости

CVSS3: 5.6
ubuntu
около 2 месяцев назад

A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.

CVSS3: 5.6
nvd
около 2 месяцев назад

A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.

CVSS3: 5.6
msrc
около 1 месяца назад

Glib: glib: buffer underflow in gvariant parser leads to heap corruption

CVSS3: 5.6
github
около 2 месяцев назад

A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.

suse-cvrf
около 1 месяца назад

Security update for glib2

EPSS

Процентиль: 57%
0.00352
Низкий