3.7 LOW
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
-
@LeSuisse
ignored
12 packages
- bootc
- loupe
- rpm-ostree
- podman-bootc
- mlxbf-bootctl
- glycin-loaders
- systemd-bootchart
- rubyPackages.glib2
- rubyPackages_3_1.glib2
- rubyPackages_3_2.glib2
- rubyPackages_3_3.glib2
- rubyPackages_3_4.glib2
- @LeSuisse published on GitHub
Glib: buffer under-read on glib through glib/gfileutils.c via get_tmp_file()
A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.
References
Affected products
Ignored packages (12)
pkgs.loupe
Simple image viewer application written with GTK4 and Rust
-
nixos-unstable -
- nixpkgs-unstable 48.1
pkgs.rpm-ostree
Hybrid image/package system. It uses OSTree as an image format, and uses RPM as a component model
-
nixos-unstable -
- nixpkgs-unstable 2024.8
pkgs.podman-bootc
Streamlining podman+bootc interactions
-
nixos-unstable -
- nixpkgs-unstable 0.1.2
pkgs.mlxbf-bootctl
Control BlueField boot partitions
-
nixos-unstable -
- nixpkgs-unstable 2025-01-16
pkgs.glycin-loaders
Glycin loaders for several formats
-
nixos-unstable -
- nixpkgs-unstable 1.2.3
pkgs.systemd-bootchart
Boot performance graphing tool from systemd
-
nixos-unstable -
- nixpkgs-unstable 235
pkgs.rubyPackages.glib2
None
-
nixos-unstable -
- nixpkgs-unstable glib2-4.3.3
pkgs.rubyPackages_3_1.glib2
None
-
nixos-unstable -
- nixpkgs-unstable glib2-4.3.3
pkgs.rubyPackages_3_2.glib2
None
-
nixos-unstable -
- nixpkgs-unstable glib2-4.3.3
pkgs.rubyPackages_3_3.glib2
None
-
nixos-unstable -
- nixpkgs-unstable glib2-4.3.3
pkgs.rubyPackages_3_4.glib2
None
-
nixos-unstable -
- nixpkgs-unstable glib2-4.3.3