SUSE-SU-2024:1950-1

Source
https://www.suse.com/support/update/announcement/2024/suse-su-20241950-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:1950-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2024:1950-1
Related
Published
2024-06-07T15:20:15Z
Modified
2024-06-07T15:20:15Z
Summary
Security update for glib2
Details

This update for glib2 fixes the following issues:

Update to version 2.78.6:

  • Fix a regression with IBus caused by the fix for CVE-2024-34397

Changes in version 2.78.5:

  • Fix CVE-2024-34397: GDBus signal subscriptions for well-known names are vulnerable to unicast spoofing. (bsc#1224044)
  • Bugs fixed:
    • gvfs-udisks2-volume-monitor SIGSEGV in gcontenttypeguessfor_tree() due to filename with bad encoding
    • gcontenttype: Make filename valid utf-8 string before processing.
    • gdbusconnection: Don't deliver signals if the sender doesn't match.

Changes in version 2.78.4:

  • Bugs fixed:
    • Fix generated RST anchors for methods, signals and properties.
    • docs/reference: depend on a native gtk-doc.
    • gobject_gdb.py: Do not break bt on optimized build.
    • gregex: clean up usage of GRegex.jitstatus.
References

Affected packages

SUSE:Linux Enterprise Module for Basesystem 15 SP6 / glib2

Package

Name
glib2
Purl
pkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.78.6-150600.4.3.1

Ecosystem specific

{
    "binaries": [
        {
            "libglib-2_0-0": "2.78.6-150600.4.3.1",
            "glib2-tools": "2.78.6-150600.4.3.1",
            "libgobject-2_0-0-32bit": "2.78.6-150600.4.3.1",
            "libgthread-2_0-0": "2.78.6-150600.4.3.1",
            "glib2-devel": "2.78.6-150600.4.3.1",
            "libgobject-2_0-0": "2.78.6-150600.4.3.1",
            "libgmodule-2_0-0": "2.78.6-150600.4.3.1",
            "libglib-2_0-0-32bit": "2.78.6-150600.4.3.1",
            "glib2-lang": "2.78.6-150600.4.3.1",
            "libgio-2_0-0": "2.78.6-150600.4.3.1",
            "gio-branding-SLE": "15-150600.35.2.1",
            "libgmodule-2_0-0-32bit": "2.78.6-150600.4.3.1",
            "libgio-2_0-0-32bit": "2.78.6-150600.4.3.1"
        }
    ]
}

SUSE:Linux Enterprise Module for Basesystem 15 SP6 / glib2-branding-SLE

Package

Name
glib2-branding-SLE
Purl
pkg:rpm/suse/glib2-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
15-150600.35.2.1

Ecosystem specific

{
    "binaries": [
        {
            "libglib-2_0-0": "2.78.6-150600.4.3.1",
            "glib2-tools": "2.78.6-150600.4.3.1",
            "libgobject-2_0-0-32bit": "2.78.6-150600.4.3.1",
            "libgthread-2_0-0": "2.78.6-150600.4.3.1",
            "glib2-devel": "2.78.6-150600.4.3.1",
            "libgobject-2_0-0": "2.78.6-150600.4.3.1",
            "libgmodule-2_0-0": "2.78.6-150600.4.3.1",
            "libglib-2_0-0-32bit": "2.78.6-150600.4.3.1",
            "glib2-lang": "2.78.6-150600.4.3.1",
            "libgio-2_0-0": "2.78.6-150600.4.3.1",
            "gio-branding-SLE": "15-150600.35.2.1",
            "libgmodule-2_0-0-32bit": "2.78.6-150600.4.3.1",
            "libgio-2_0-0-32bit": "2.78.6-150600.4.3.1"
        }
    ]
}

openSUSE:Leap 15.6 / glib2

Package

Name
glib2
Purl
pkg:rpm/opensuse/glib2&distro=openSUSE%20Leap%2015.6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.78.6-150600.4.3.1

Ecosystem specific

{
    "binaries": [
        {
            "libglib-2_0-0": "2.78.6-150600.4.3.1",
            "libgobject-2_0-0-32bit": "2.78.6-150600.4.3.1",
            "glib2-devel-32bit": "2.78.6-150600.4.3.1",
            "gio-branding-SLE": "15-150600.35.2.1",
            "glib2-devel-static": "2.78.6-150600.4.3.1",
            "glib2-devel": "2.78.6-150600.4.3.1",
            "libgobject-2_0-0": "2.78.6-150600.4.3.1",
            "gio-branding-upstream": "2.78.6-150600.4.3.1",
            "libgmodule-2_0-0": "2.78.6-150600.4.3.1",
            "glib2-lang": "2.78.6-150600.4.3.1",
            "libgthread-2_0-0-32bit": "2.78.6-150600.4.3.1",
            "glib2-tools": "2.78.6-150600.4.3.1",
            "libgthread-2_0-0": "2.78.6-150600.4.3.1",
            "libglib-2_0-0-32bit": "2.78.6-150600.4.3.1",
            "libgio-2_0-0": "2.78.6-150600.4.3.1",
            "glib2-doc": "2.78.6-150600.4.3.1",
            "glib2-tests-devel": "2.78.6-150600.4.3.1",
            "libgmodule-2_0-0-32bit": "2.78.6-150600.4.3.1",
            "glib2-tools-32bit": "2.78.6-150600.4.3.1",
            "libgio-2_0-0-32bit": "2.78.6-150600.4.3.1"
        }
    ]
}

openSUSE:Leap 15.6 / glib2-branding-SLE

Package

Name
glib2-branding-SLE
Purl
pkg:rpm/opensuse/glib2-branding-SLE&distro=openSUSE%20Leap%2015.6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
15-150600.35.2.1

Ecosystem specific

{
    "binaries": [
        {
            "libglib-2_0-0": "2.78.6-150600.4.3.1",
            "libgobject-2_0-0-32bit": "2.78.6-150600.4.3.1",
            "glib2-devel-32bit": "2.78.6-150600.4.3.1",
            "gio-branding-SLE": "15-150600.35.2.1",
            "glib2-devel-static": "2.78.6-150600.4.3.1",
            "glib2-devel": "2.78.6-150600.4.3.1",
            "libgobject-2_0-0": "2.78.6-150600.4.3.1",
            "gio-branding-upstream": "2.78.6-150600.4.3.1",
            "libgmodule-2_0-0": "2.78.6-150600.4.3.1",
            "glib2-lang": "2.78.6-150600.4.3.1",
            "libgthread-2_0-0-32bit": "2.78.6-150600.4.3.1",
            "glib2-tools": "2.78.6-150600.4.3.1",
            "libgthread-2_0-0": "2.78.6-150600.4.3.1",
            "libglib-2_0-0-32bit": "2.78.6-150600.4.3.1",
            "libgio-2_0-0": "2.78.6-150600.4.3.1",
            "glib2-doc": "2.78.6-150600.4.3.1",
            "glib2-tests-devel": "2.78.6-150600.4.3.1",
            "libgmodule-2_0-0-32bit": "2.78.6-150600.4.3.1",
            "glib2-tools-32bit": "2.78.6-150600.4.3.1",
            "libgio-2_0-0-32bit": "2.78.6-150600.4.3.1"
        }
    ]
}

openSUSE:Leap 15.6 / glib2-doc

Package

Name
glib2-doc
Purl
pkg:rpm/opensuse/glib2-doc&distro=openSUSE%20Leap%2015.6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.78.6-150600.4.3.1

Ecosystem specific

{
    "binaries": [
        {
            "libglib-2_0-0": "2.78.6-150600.4.3.1",
            "libgobject-2_0-0-32bit": "2.78.6-150600.4.3.1",
            "glib2-devel-32bit": "2.78.6-150600.4.3.1",
            "gio-branding-SLE": "15-150600.35.2.1",
            "glib2-devel-static": "2.78.6-150600.4.3.1",
            "glib2-devel": "2.78.6-150600.4.3.1",
            "libgobject-2_0-0": "2.78.6-150600.4.3.1",
            "gio-branding-upstream": "2.78.6-150600.4.3.1",
            "libgmodule-2_0-0": "2.78.6-150600.4.3.1",
            "glib2-lang": "2.78.6-150600.4.3.1",
            "libgthread-2_0-0-32bit": "2.78.6-150600.4.3.1",
            "glib2-tools": "2.78.6-150600.4.3.1",
            "libgthread-2_0-0": "2.78.6-150600.4.3.1",
            "libglib-2_0-0-32bit": "2.78.6-150600.4.3.1",
            "libgio-2_0-0": "2.78.6-150600.4.3.1",
            "glib2-doc": "2.78.6-150600.4.3.1",
            "glib2-tests-devel": "2.78.6-150600.4.3.1",
            "libgmodule-2_0-0-32bit": "2.78.6-150600.4.3.1",
            "glib2-tools-32bit": "2.78.6-150600.4.3.1",
            "libgio-2_0-0-32bit": "2.78.6-150600.4.3.1"
        }
    ]
}