Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-16429

Опубликовано: 04 сент. 2018
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().

Отчет

The glib2 package in Red Hat Enterprise Linux 8 is not affected by this vulnerability because a newer and fixed version is shipped.

Меры по смягчению последствий

Since the only affected code in this flaw is g_markup_parse_context_parse(), any application (compiled with glib2) which does not use this function or any other function which calls this vulnerable code, is not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5firefoxWill not fix
Red Hat Enterprise Linux 5glib2Will not fix
Red Hat Enterprise Linux 6firefoxWill not fix
Red Hat Enterprise Linux 6glib2Will not fix
Red Hat Enterprise Linux 6thunderbirdWill not fix
Red Hat Enterprise Linux 7firefoxWill not fix
Red Hat Enterprise Linux 7glib2Fix deferred
Red Hat Enterprise Linux 7thunderbirdWill not fix
Red Hat Enterprise Linux 8firefoxNot affected
Red Hat Enterprise Linux 8glib2Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1626148glib2: Out-of-bounds read in g_markup_parse_context_parse() in gmarkup.c

EPSS

Процентиль: 63%
0.00458
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().

CVSS3: 7.5
nvd
больше 7 лет назад

GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().

CVSS3: 7.5
debian
больше 7 лет назад

GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_ ...

suse-cvrf
около 7 лет назад

Security update for glib2

CVSS3: 7.5
github
больше 3 лет назад

GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().

EPSS

Процентиль: 63%
0.00458
Низкий

7.5 High

CVSS3