QID 198294

Date Published: 2021-03-25

QID 198294: Ubuntu Security Notification for Glib2.0 Vulnerability (USN-4764-1)

It was discovered that GLib incorrectly handled certain symlinks when replacing files.

If a user or automated system were tricked into extracting a specially crafted file with File Roller, a remote attacker could possibly create files outside of the intended directory.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Refer to Ubuntu advisory USN-4764-1 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 198294

    Software Advisories
    Advisory ID Software Component Link
    USN-4764-1 16.04 (Xenial) on src libglib2.0-0 URL Logo launchpad.net/ubuntu/+source/glib2.0/2.48.2-0ubuntu4.8
    USN-4764-1 18.04 (bionic) on src libglib2.0-0 URL Logo launchpad.net/ubuntu/+source/glib2.0/2.56.4-0ubuntu0.18.04.8
    USN-4764-1 20.04 (focal) on src libglib2.0-0 URL Logo launchpad.net/ubuntu/+source/glib2.0/2.64.6-1~ubuntu20.04.3
    USN-4764-1 20.10 (groovy) on src libglib2.0-0 URL Logo launchpad.net/ubuntu/+source/glib2.0/2.66.1-2ubuntu0.2