Advisories ยป MGASA-2021-0318

Updated glib2.0 packages fix security vulnerabilities

Publication date: 08 Jul 2021
Modification date: 08 Jul 2021
Type: security
Affected Mageia releases : 7
CVE: CVE-2021-27218 , CVE-2021-27219 , CVE-2021-28153

Description

Krzesimir Nowak discovered that GLib incorrectly handled certain large
buffers. A remote attacker could use this issue to cause applications linked
to GLib to crash, resulting in a denial of service, or possibly execute
arbitrary code (CVE-2021-27218).

Kevin Backhouse discovered that GLib incorrectly handled certain memory
allocations. A remote attacker could use this issue to cause applications
linked to GLib to crash, resulting in a denial of service, or possibly execute
arbitrary code (CVE-2021-27219).

It was discovered that GLib incorrectly handled certain symlinks when
replacing files. If a user or automated system were tricked into extracting a
specially crafted file with File Roller, a remote attacker could possibly
create files outside of the intended directory (CVE-2021-28153).
                

References

SRPMS

7/core