Technical information leak In glib2.0
Description
A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS).
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 2.74.6-2+deb12u9 | ||
debian 14 | 2.86.3-5 | ||
debian 13 | 2.84.4-3~deb13u3 | ||
debian 11 | 2.66.8-1+deb11u8 | ||
rpm rhel10 | - | - | |
rpm rhel9 | - | - | |
rpm rhel9 | - | - | |
rpm rhel10 | - | - | |
rpm rhel10 | - | - | |
rpm rhel6 | - | - |
1-10 of 20
10
Aliases
1. 2. 3. 4. 5.