Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-6052

Опубликовано: 13 июн. 2025
Источник: nvd
CVSS3: 3.7
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the allocated memory, leading to crashes or memory corruption.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*
Версия от 2.75.3 (включая) до 2.84.3 (включая)

EPSS

Процентиль: 14%
0.00047
Низкий

3.7 Low

CVSS3

7.5 High

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 3.7
ubuntu
6 месяцев назад

A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the allocated memory, leading to crashes or memory corruption.

CVSS3: 3.7
redhat
6 месяцев назад

A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the allocated memory, leading to crashes or memory corruption.

CVSS3: 3.7
msrc
3 месяца назад

Glib: integer overflow in g_string_maybe_expand() leading to potential buffer overflow in glib gstring

CVSS3: 3.7
debian
6 месяцев назад

A flaw was found in how GLib\u2019s GString manages memory when adding ...

CVSS3: 3.7
github
6 месяцев назад

A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the allocated memory, leading to crashes or memory corruption.

EPSS

Процентиль: 14%
0.00047
Низкий

3.7 Low

CVSS3

7.5 High

CVSS3

Дефекты

CWE-190