Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-52533

Опубликовано: 11 нояб. 2024
Источник: redhat
CVSS3: 7

Описание

gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.

A flaw was found in the Glib library. A buffer overflow condition can be triggered in certain conditions due to an off-by-one error in SOCKS4_CONN_MSG_LEN. This issue may lead to an application crash or other undefined behavior.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10mingw-glib2Not affected
Red Hat Enterprise Linux 7glib2Out of support scope
Red Hat Enterprise Linux 8mingw-glib2Will not fix
Red Hat Enterprise Linux 10glib2FixedRHSA-2025:1085514.07.2025
Red Hat Enterprise Linux 8glib2FixedRHSA-2025:1132716.07.2025
Red Hat Enterprise Linux 9glib2FixedRHSA-2025:1114015.07.2025
Red Hat Enterprise Linux 9mingw-glib2FixedRHSA-2025:093604.02.2025
Red Hat Enterprise Linux 9glib2FixedRHSA-2025:1114015.07.2025
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutionsglib2FixedRHSA-2025:1137317.07.2025
Red Hat Enterprise Linux 9.4 Extended Update Supportglib2FixedRHSA-2025:1137417.07.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-193
https://bugzilla.redhat.com/show_bug.cgi?id=2325340glib: buffer overflow in set_connect_msg()

7 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
9 месяцев назад

gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.

CVSS3: 9.8
nvd
9 месяцев назад

gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.

CVSS3: 9.8
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 9.8
debian
9 месяцев назад

gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one erro ...

suse-cvrf
8 месяцев назад

Security update for glib2

7 High

CVSS3