Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-11327

Опубликовано: 16 июл. 2025
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2025-11327: glib2 security update (MODERATE)

[2.56.4-166]

  • Add patches for CVE-2024-34397, CVE-2024-52533, CVE-2025-4373
  • Update GDateTime test for new tzdata
  • Resolves: RHEL-67084
  • Resolves: RHEL-94286
  • Resolves: RHEL-94848

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

glib2-doc

2.56.4-166.el8_10

glib2-static

2.56.4-166.el8_10

glib2

2.56.4-166.el8_10

glib2-devel

2.56.4-166.el8_10

glib2-fam

2.56.4-166.el8_10

glib2-tests

2.56.4-166.el8_10

Oracle Linux x86_64

glib2-doc

2.56.4-166.el8_10

glib2-static

2.56.4-166.el8_10

glib2

2.56.4-166.el8_10

glib2-devel

2.56.4-166.el8_10

glib2-fam

2.56.4-166.el8_10

glib2-tests

2.56.4-166.el8_10

Связанные уязвимости

oracle-oval
28 дней назад

ELSA-2025-11140: glib2 security update (MODERATE)

oracle-oval
27 дней назад

ELSA-2025-10855: glib2 security update (MODERATE)

CVSS3: 5.2
ubuntu
больше 1 года назад

An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.

CVSS3: 3.8
redhat
больше 1 года назад

An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.

CVSS3: 5.2
nvd
больше 1 года назад

An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.