REDHAT-BUG-2325340: Buffer Overflow
Published Nov 11, 2024
·Updated
gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4CONNMSGLEN is not sufficient for a trailing '\0' character.
Affected Software
1 affected component
Gnome GLib<2.82.1
Event History
Nov 11, 2024
Data Sourced
via Red Hat·11:01 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2325340?
The vulnerability REDHAT-BUG-2325340 is considered to be high severity due to the potential for a buffer overflow.
2
How do I fix REDHAT-BUG-2325340?
To fix REDHAT-BUG-2325340, upgrade GNOME GLib to version 2.82.1 or later.
3
What are the consequences of REDHAT-BUG-2325340?
The consequences of REDHAT-BUG-2325340 include potential exploitation leading to application crashes or arbitrary code execution.
4
Which versions of GNOME GLib are affected by REDHAT-BUG-2325340?
Versions of GNOME GLib prior to 2.82.1 are affected by REDHAT-BUG-2325340.
5
Is there a known exploit for REDHAT-BUG-2325340?
As of now, there are no publicly known exploits for REDHAT-BUG-2325340, but the vulnerability does pose significant risks if left unpatched.