Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-6464

Опубликовано: 09 сент. 2024
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2024-6464: glib2 security update (MODERATE)

[2.68.4-14.1]

  • Fix CVE-2024-34397, signal subscription vulnerabilities
  • Resolves: RHEL-56979

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

glib2

2.68.4-14.el9_4.1

glib2-devel

2.68.4-14.el9_4.1

glib2-doc

2.68.4-14.el9_4.1

glib2-static

2.68.4-14.el9_4.1

glib2-tests

2.68.4-14.el9_4.1

Oracle Linux x86_64

glib2

2.68.4-14.el9_4.1

glib2-devel

2.68.4-14.el9_4.1

glib2-doc

2.68.4-14.el9_4.1

glib2-static

2.68.4-14.el9_4.1

glib2-tests

2.68.4-14.el9_4.1

Связанные CVE

Связанные уязвимости

CVSS3: 5.2
ubuntu
около 1 года назад

An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.

CVSS3: 3.8
redhat
около 1 года назад

An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.

CVSS3: 5.2
nvd
около 1 года назад

An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.

CVSS3: 5.2
msrc
3 месяца назад

Описание отсутствует

CVSS3: 5.2
debian
около 1 года назад

An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2. ...