Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-35457

Опубликовано: 14 дек. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.6
CVSS3: 7.8

Описание

GNOME GLib before 2.65.3 has an integer overflow, that might lead to an out-of-bounds write, in g_option_group_add_entries. NOTE: the vendor's position is "Realistically this is not a security issue. The standard pattern is for callers to provide a static list of option entries in a fixed number of calls to g_option_group_add_entries()." The researcher states that this pattern is undocumented

РелизСтатусПримечание
bionic

not-affected

disputed
devel

not-affected

esm-infra-legacy/trusty

not-affected

disputed
esm-infra/bionic

not-affected

disputed
esm-infra/focal

not-affected

disputed
esm-infra/xenial

not-affected

disputed
focal

not-affected

disputed
groovy

not-affected

2.66.1-2
precise/esm

not-affected

disputed
trusty

ignored

end of standard support

Показывать по

EPSS

Процентиль: 45%
0.00225
Низкий

4.6 Medium

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
больше 4 лет назад

GNOME GLib before 2.65.3 has an integer overflow, that might lead to an out-of-bounds write, in g_option_group_add_entries. NOTE: the vendor's position is "Realistically this is not a security issue. The standard pattern is for callers to provide a static list of option entries in a fixed number of calls to g_option_group_add_entries()." The researcher states that this pattern is undocumented

CVSS3: 7.8
debian
больше 4 лет назад

GNOME GLib before 2.65.3 has an integer overflow, that might lead to a ...

CVSS3: 7.8
github
больше 3 лет назад

** DISPUTED ** GNOME GLib before 2.65.3 has an integer overflow, that might lead to an out-of-bounds write, in g_option_group_add_entries. NOTE: the vendor's position is "Realistically this is not a security issue. The standard pattern is for callers to provide a static list of option entries in a fixed number of calls to g_option_group_add_entries()." The researcher states that this pattern is undocumented.

CVSS3: 7.8
fstec
почти 5 лет назад

Уязвимость функции g_option_group_add_entries() библиотеки Glib, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 45%
0.00225
Низкий

4.6 Medium

CVSS2

7.8 High

CVSS3