CVE-2023-32643

Updated: 2023-11-04 21:01:37.753967

Description:

A flaw was found in GLib. The GVariant deserialization code is vulnerable to a heap buffer overflow introduced by the fix for CVE-2023-32665. This bug does not affect any released version of GLib, but does affect GLib distributors who followed the guidance of GLib developers to backport the initial fix for CVE-2023-32665.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated
AlmaLinux 9.2 ESU glib2 2.68.4 7.8 HIGH Not Vulnerable 2023-11-08 08:36:05
CentOS 6 ELS glib2 2.28.8 7.8 HIGH Not Vulnerable 2023-10-25 17:07:09
CentOS 7 ELS glib2 2.56.1 7.8 HIGH Released CLSA-2023:1697135256 2023-10-12 17:08:07
CentOS 8.4 ELS glib2 2.56.4-10 7.8 HIGH Released CLSA-2023:1697740212 2023-10-19 21:08:35
CentOS 8.5 ELS glib2 2.56.4-156 7.8 HIGH Released CLSA-2023:1697740947 2023-10-19 21:08:34
CloudLinux 6 ELS glib2 2.28.8 7.8 HIGH Not Vulnerable 2023-10-25 17:07:09
Oracle Linux 6 ELS glib2 2.28.8 7.8 HIGH Not Vulnerable 2023-10-25 17:07:09
Ubuntu 16.04 ELS glib2.0 2.48.2-0 7.8 HIGH Released CLSA-2023:1697741722 2023-10-19 21:08:41
Ubuntu 18.04 ELS glib2.0 2.56.4-0 7.8 HIGH Released CLSA-2023:1697741849 2023-10-19 21:08:43