CVE-2024-52533

Name
CVE-2024-52533
Description
gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home
https://gitlab.gnome.org/GNOME/glib/-/issues/3461
https://gitlab.gnome.org/GNOME/glib/-/releases/2.82.1
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2024/11/12/11
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2024/11/msg00020.html
af854a3a-2127-422b-91ae-364da2661108 https://security.netapp.com/advisory/ntap-20241206-0009/

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
glib 3.20-main 2.80.5-r0 Pablo Correa Gómez <ablocorrea@hotmail.com> possibly vulnerable
glib 3.19-main 2.78.6-r0 Pablo Correa Gómez <ablocorrea@hotmail.com> possibly vulnerable
glib 3.18-main 2.76.6-r0 Rasmus Thomsen <oss@cogitri.dev> possibly vulnerable
glib 3.17-main 2.74.7-r0 Rasmus Thomsen <oss@cogitri.dev> possibly vulnerable