Updated: 2022-12-07 20:03:23.626717
Description:
An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could potentially lead to memory corruption.
Links | NIST | CIRCL | RHEL | Ubuntu |
Severity | Score | |
---|---|---|
CVSS Version 2.x | MEDIUM | 5 |
CVSS Version 3.x | HIGH | 7.5 |
OS name | Project name | Version | Score | Severity | Status | Errata | Last updated |
---|---|---|---|---|---|---|---|
CentOS 6 ELS | glib2 | 2.28.8 | 7.5 | HIGH | Released | CLSA-2021:1623075923 | 2022-05-05 12:38:32 |
CentOS 8.4 ELS | glib2 | 2.56.4-10 | 7.5 | HIGH | Not Vulnerable | 2022-02-14 17:48:07 | |
CentOS 8.5 ELS | glib2 | 2.56.4-156 | 7.5 | HIGH | Not Vulnerable | 2022-02-14 17:48:07 | |
CloudLinux 6 ELS | glib2 | 2.28.8 | 7.5 | HIGH | Released | 2021-12-09 07:57:03 | |
Oracle Linux 6 ELS | glib2 | 2.28.8 | 7.5 | HIGH | Released | 2021-12-09 07:57:03 | |
Ubuntu 16.04 ELS | glib2 | 2.48.2-0 | 7.5 | HIGH | Not Vulnerable | 2021-12-09 07:57:03 | |
Ubuntu 18.04 ELS | glib2 | 2.56.4-0 | 7.5 | HIGH | Needs Triage | 2023-03-02 13:00:59 |