Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-9633

Опубликовано: 29 янв. 2019
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

gio/gsocketclient.c in GNOME GLib 2.59.2 does not ensure that a parent GTask remains alive during the execution of a connection-attempting enumeration, which allows remote attackers to cause a denial of service (g_socket_client_connected_callback mishandling and application crash) via a crafted web site, as demonstrated by GNOME Web (aka Epiphany).

Отчет

This issue affects only the versions of glib2-2.59.1 and is fixed in version 2.59.2. The 2.59.1 was an unstable release and wasn't shipped with Red Hat Enterprise Linux 6, 7 and 8, hence Red Hat Enterprise Linux is not affected by this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5glibNot affected
Red Hat Enterprise Linux 5glib2Not affected
Red Hat Enterprise Linux 6chromium-browserNot affected
Red Hat Enterprise Linux 6firefoxNot affected
Red Hat Enterprise Linux 6glib2Not affected
Red Hat Enterprise Linux 6thunderbirdNot affected
Red Hat Enterprise Linux 7glib2Not affected
Red Hat Enterprise Linux 8glib2Not affected
Red Hat Enterprise Linux 8mingw-glib2Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20->CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1687805glib: g_socket_client_connected_callback in gio/gsocketclient.c allows to cause denial of service

EPSS

Процентиль: 70%
0.00654
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 7 лет назад

gio/gsocketclient.c in GNOME GLib 2.59.2 does not ensure that a parent GTask remains alive during the execution of a connection-attempting enumeration, which allows remote attackers to cause a denial of service (g_socket_client_connected_callback mishandling and application crash) via a crafted web site, as demonstrated by GNOME Web (aka Epiphany).

CVSS3: 6.5
nvd
почти 7 лет назад

gio/gsocketclient.c in GNOME GLib 2.59.2 does not ensure that a parent GTask remains alive during the execution of a connection-attempting enumeration, which allows remote attackers to cause a denial of service (g_socket_client_connected_callback mishandling and application crash) via a crafted web site, as demonstrated by GNOME Web (aka Epiphany).

CVSS3: 6.5
debian
почти 7 лет назад

gio/gsocketclient.c in GNOME GLib 2.59.2 does not ensure that a parent ...

CVSS3: 6.5
github
больше 3 лет назад

gio/gsocketclient.c in GNOME GLib 2.59.2 does not ensure that a parent GTask remains alive during the execution of a connection-attempting enumeration, which allows remote attackers to cause a denial of service (g_socket_client_connected_callback mishandling and application crash) via a crafted web site, as demonstrated by GNOME Web (aka Epiphany).

EPSS

Процентиль: 70%
0.00654
Низкий

8.2 High

CVSS3