CVE-2024-34397

Name
CVE-2024-34397
Description
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://gitlab.gnome.org/GNOME/glib/-/issues/3268
cve@mitre.org https://www.openwall.com/lists/oss-security/2024/05/07/5
vendor-advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IRSFYAE5X23TNRWX7ZWEJOMISLCDSYNS/
vendor-advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UNFJHISR4O6VFOHBFWH5I5WWMG37H63A/
mailing-list https://lists.debian.org/debian-lts-announce/2024/05/msg00008.html
https://security.netapp.com/advisory/ntap-20240531-0008/
vendor-advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LL6HSJDXCXMLEIJBYV6CPOR4K2NTCTXW/
vendor-advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LCDY3KA7G7D3DRXYTT46K6LFHS2KHWBH/
af854a3a-2127-422b-91ae-364da2661108 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IRSFYAE5X23TNRWX7ZWEJOMISLCDSYNS/
af854a3a-2127-422b-91ae-364da2661108 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LCDY3KA7G7D3DRXYTT46K6LFHS2KHWBH/
af854a3a-2127-422b-91ae-364da2661108 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UNFJHISR4O6VFOHBFWH5I5WWMG37H63A/
af854a3a-2127-422b-91ae-364da2661108 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LL6HSJDXCXMLEIJBYV6CPOR4K2NTCTXW/
0b142b55-0307-4c5a-b3c9-f314f3fb7c5e https://cert-portal.siemens.com/productcert/html/ssa-082556.html
0b142b55-0307-4c5a-b3c9-f314f3fb7c5e https://cert-portal.siemens.com/productcert/html/ssa-613116.html

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a
cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:* glib >= None < 2.78.5
cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:* glib >= 2.79.0 < 2.80.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
glib edge-main 2.80.1-r0 Pablo Correa Gómez <ablocorrea@hotmail.com> fixed
glib edge-main 2.66.6-r0 None possibly vulnerable
glib edge-main 2.62.5-r0 None possibly vulnerable
glib edge-main 2.60.4-r0 None possibly vulnerable
glib 3.22-main 2.80.1-r0 None fixed
glib 3.22-main 2.66.6-r0 None possibly vulnerable
glib 3.22-main 2.62.5-r0 None possibly vulnerable
glib 3.22-main 2.60.4-r0 None possibly vulnerable
glib 3.21-main 2.80.1-r0 None fixed
glib 3.21-main 2.66.6-r0 None possibly vulnerable
glib 3.21-main 2.62.5-r0 None possibly vulnerable
glib 3.21-main 2.60.4-r0 None possibly vulnerable
glib 3.20-main 2.80.1-r0 None fixed
glib 3.20-main 2.66.6-r0 None possibly vulnerable
glib 3.20-main 2.62.5-r0 None possibly vulnerable
glib 3.20-main 2.60.4-r0 None possibly vulnerable
glib 3.19-main 2.78.5-r0 Pablo Correa Gómez <ablocorrea@hotmail.com> fixed
glib 3.19-main 2.66.6-r0 None possibly vulnerable
glib 3.19-main 2.62.5-r0 None possibly vulnerable
glib 3.19-main 2.60.4-r0 None possibly vulnerable