Updated glib2.0 packages fix security vulnerabilities
Publication date: 08 Jul 2021Modification date: 08 Jul 2021
Type: security
Affected Mageia releases : 7
CVE: CVE-2021-27218 , CVE-2021-27219 , CVE-2021-28153
Description
Krzesimir Nowak discovered that GLib incorrectly handled certain large
buffers. A remote attacker could use this issue to cause applications linked
to GLib to crash, resulting in a denial of service, or possibly execute
arbitrary code (CVE-2021-27218).
Kevin Backhouse discovered that GLib incorrectly handled certain memory
allocations. A remote attacker could use this issue to cause applications
linked to GLib to crash, resulting in a denial of service, or possibly execute
arbitrary code (CVE-2021-27219).
It was discovered that GLib incorrectly handled certain symlinks when
replacing files. If a user or automated system were tricked into extracting a
specially crafted file with File Roller, a remote attacker could possibly
create files outside of the intended directory (CVE-2021-28153).
References
- https://bugs.mageia.org/show_bug.cgi?id=28520
- https://ubuntu.com/security/notices/USN-4759-1
- https://ubuntu.com/security/notices/USN-4764-1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27218
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27219
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28153
SRPMS
7/core
- glib2.0-2.60.2-1.5.mga7