LWN.net Logo

glib: attacker-supplied code execution

Package(s):glib CVE #(s):CVE-2008-4316
Created:March 13, 2009 Updated:April 24, 2009
Description: From the rPath advisory: Previous versions of glib contain a vulnerability in the base64 encode and decode functions which may result in executing attacker-supplied code when processing large strings. This vulnerability is present only through applications that accept user-supplied strings and process them with the base64 encode or decode functionality of glib.
Alerts:
Gentoo 200904-02 2009-04-03
Mandriva MDVSA-2009:085 2009-04-02
Fedora FEDORA-2009-2688 2009-03-13
Slackware SSA:2009-086-02 2009-03-30
Mandriva MDVSA-2009:080 2009-03-26
Red Hat RHSA-2009:0336-01 2009-03-24
Debian DSA-1747-1 2009-03-20
Ubuntu USN-738-1 2009-03-16
rPath rPSA-2009-0045-1 2009-03-12
Fedora FEDORA-2009-2657 2009-03-13
SuSE SUSE-SA:2009:026 2009-04-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds