QID 670991
Date Published: 2021-11-24
QID 670991: EulerOS Security Update for glib2 (EulerOS-SA-2021-2580)
GLib is the low-level core library that forms the basis for projects such as GTK+ and GNOME. It provides data structure handling for C, portability wrappers, and interfaces for such runtime functionality as an event loop, threads, dynamic loading, and an object system.
Security Fix(es):
GNOME GLib before 2.65.3 has an integer overflow, that might lead to an out-of-bounds write, in g_option_group_add_entries. NOTE: the vendor's position is "Realistically this is not a security issue. The standard pattern is for callers to provide a static list of option entries in a fixed number of calls to g_option_group_add_entries()." The researcher states that this pattern is undocumented.(CVE-2020-35457)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
An arbitrary attacker may exploit this vulnerability to compromise the system.
CVEs related to QID 670991
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| EulerOS-SA-2021-2580 | EulerOS V2.0SP3 |
|