摘要:
GLib s GVariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of GLib, but does affect GLib distributors who followed the guidance of GLib developers to backport the initial fix for CVE-2023-29499References:https://gitlab.gnome.org/GNOME/glib/-/issues/2841
安全等级: Low
公告ID: KylinSec-SA-2023-1402
发布日期: 2023年6月9日
关联CVE: CVE-2023-32636
GLib s GVariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of GLib, but does affect GLib distributors who followed the guidance of GLib developers to backport the initial fix for CVE-2023-29499References:https://gitlab.gnome.org/GNOME/glib/-/issues/2841
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2023-32636 | KY3.4-4A | glib2 | Unaffected |
CVE-2023-32636 | KY3.4-5A | glib2 | Unaffected |
CVE-2023-32636 | KY3.5.1 | glib2 | Unaffected |
CVE-2023-32636 | KY3.5.2 | glib2 | Unaffected |