A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.
{
"binaries": [
{
"binary_version": "2.72.4-0ubuntu2.9",
"binary_name": "libglib2.0-0"
},
{
"binary_version": "2.72.4-0ubuntu2.9",
"binary_name": "libglib2.0-bin"
},
{
"binary_version": "2.72.4-0ubuntu2.9",
"binary_name": "libglib2.0-data"
},
{
"binary_version": "2.72.4-0ubuntu2.9",
"binary_name": "libglib2.0-dev-bin"
},
{
"binary_version": "2.72.4-0ubuntu2.9",
"binary_name": "libglib2.0-tests"
}
],
"availability": "No subscription required"
}{
"binaries": [
{
"binary_version": "2.80.0-6ubuntu3.8",
"binary_name": "gir1.2-girepository-3.0"
},
{
"binary_version": "2.80.0-6ubuntu3.8",
"binary_name": "gir1.2-glib-2.0"
},
{
"binary_version": "2.80.0-6ubuntu3.8",
"binary_name": "libgirepository-2.0-0"
},
{
"binary_version": "2.80.0-6ubuntu3.8",
"binary_name": "libglib2.0-0t64"
},
{
"binary_version": "2.80.0-6ubuntu3.8",
"binary_name": "libglib2.0-bin"
},
{
"binary_version": "2.80.0-6ubuntu3.8",
"binary_name": "libglib2.0-data"
},
{
"binary_version": "2.80.0-6ubuntu3.8",
"binary_name": "libglib2.0-dev-bin"
},
{
"binary_version": "2.80.0-6ubuntu3.8",
"binary_name": "libglib2.0-tests"
}
],
"availability": "No subscription required"
}{
"binaries": [
{
"binary_version": "2.86.0-2ubuntu0.3",
"binary_name": "gir1.2-girepository-3.0"
},
{
"binary_version": "2.86.0-2ubuntu0.3",
"binary_name": "gir1.2-glib-2.0"
},
{
"binary_version": "2.86.0-2ubuntu0.3",
"binary_name": "girepository-tools"
},
{
"binary_version": "2.86.0-2ubuntu0.3",
"binary_name": "libgio-2.0-dev-bin"
},
{
"binary_version": "2.86.0-2ubuntu0.3",
"binary_name": "libgirepository-2.0-0"
},
{
"binary_version": "2.86.0-2ubuntu0.3",
"binary_name": "libglib2.0-0t64"
},
{
"binary_version": "2.86.0-2ubuntu0.3",
"binary_name": "libglib2.0-bin"
},
{
"binary_version": "2.86.0-2ubuntu0.3",
"binary_name": "libglib2.0-data"
},
{
"binary_version": "2.86.0-2ubuntu0.3",
"binary_name": "libglib2.0-dev-bin"
},
{
"binary_version": "2.86.0-2ubuntu0.3",
"binary_name": "libglib2.0-tests"
}
],
"availability": "No subscription required"
}{
"binaries": [
{
"binary_version": "2.40.2-0ubuntu1.1+esm7",
"binary_name": "libglib2.0-0"
},
{
"binary_version": "2.40.2-0ubuntu1.1+esm7",
"binary_name": "libglib2.0-0-refdbg"
},
{
"binary_version": "2.40.2-0ubuntu1.1+esm7",
"binary_name": "libglib2.0-bin"
},
{
"binary_version": "2.40.2-0ubuntu1.1+esm7",
"binary_name": "libglib2.0-data"
},
{
"binary_version": "2.40.2-0ubuntu1.1+esm7",
"binary_name": "libglib2.0-tests"
}
]
}{
"binaries": [
{
"binary_version": "2.48.2-0ubuntu4.8+esm5",
"binary_name": "libglib2.0-0"
},
{
"binary_version": "2.48.2-0ubuntu4.8+esm5",
"binary_name": "libglib2.0-0-refdbg"
},
{
"binary_version": "2.48.2-0ubuntu4.8+esm5",
"binary_name": "libglib2.0-bin"
},
{
"binary_version": "2.48.2-0ubuntu4.8+esm5",
"binary_name": "libglib2.0-data"
},
{
"binary_version": "2.48.2-0ubuntu4.8+esm5",
"binary_name": "libglib2.0-tests"
}
]
}{
"binaries": [
{
"binary_version": "2.56.4-0ubuntu0.18.04.9+esm5",
"binary_name": "libglib2.0-0"
},
{
"binary_version": "2.56.4-0ubuntu0.18.04.9+esm5",
"binary_name": "libglib2.0-bin"
},
{
"binary_version": "2.56.4-0ubuntu0.18.04.9+esm5",
"binary_name": "libglib2.0-data"
},
{
"binary_version": "2.56.4-0ubuntu0.18.04.9+esm5",
"binary_name": "libglib2.0-dev-bin"
},
{
"binary_version": "2.56.4-0ubuntu0.18.04.9+esm5",
"binary_name": "libglib2.0-tests"
}
]
}{
"binaries": [
{
"binary_version": "2.64.6-1~ubuntu20.04.9+esm1",
"binary_name": "libglib2.0-0"
},
{
"binary_version": "2.64.6-1~ubuntu20.04.9+esm1",
"binary_name": "libglib2.0-bin"
},
{
"binary_version": "2.64.6-1~ubuntu20.04.9+esm1",
"binary_name": "libglib2.0-data"
},
{
"binary_version": "2.64.6-1~ubuntu20.04.9+esm1",
"binary_name": "libglib2.0-dev-bin"
},
{
"binary_version": "2.64.6-1~ubuntu20.04.9+esm1",
"binary_name": "libglib2.0-tests"
}
]
}