Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-14512

Опубликовано: 11 дек. 2025
Источник: debian

Описание

A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
glib2.0fixed2.86.3-1package
glib2.0fixed2.84.4-3~deb13u2trixiepackage
glib2.0fixed2.74.6-2+deb12u8bookwormpackage

Примечания

  • https://gitlab.gnome.org/GNOME/glib/-/issues/3845

  • https://gitlab.gnome.org/GNOME/glib/-/merge_requests/4935

  • https://gitlab.gnome.org/GNOME/glib/-/merge_requests/4936

  • Fixed by: https://gitlab.gnome.org/GNOME/glib/-/commit/4f0399c0aaf3ffc86b5625424580294bc7460404 (2.86.3)

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 месяцев назад

A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.

CVSS3: 6.5
nvd
около 2 месяцев назад

A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.

CVSS3: 6.5
msrc
около 2 месяцев назад

Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow

CVSS3: 6.5
github
около 2 месяцев назад

A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.

suse-cvrf
около 1 месяца назад

Security update for glib2