Описание
ELSA-2024-6464: glib2 security update (MODERATE)
[2.68.4-14.1]
- Fix CVE-2024-34397, signal subscription vulnerabilities
- Resolves: RHEL-56979
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
glib2
2.68.4-14.el9_4.1
glib2-devel
2.68.4-14.el9_4.1
glib2-doc
2.68.4-14.el9_4.1
glib2-static
2.68.4-14.el9_4.1
glib2-tests
2.68.4-14.el9_4.1
Oracle Linux x86_64
glib2
2.68.4-14.el9_4.1
glib2-devel
2.68.4-14.el9_4.1
glib2-doc
2.68.4-14.el9_4.1
glib2-static
2.68.4-14.el9_4.1
glib2-tests
2.68.4-14.el9_4.1
Связанные CVE
Связанные уязвимости
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2. ...