[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256610

 
 

909

 
 

199263

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2024-34397Date: (C)2024-05-08   (M)2024-06-18


An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 3.8CVSS Score :
Exploit Score: Exploit Score:
Impact Score: Impact Score:
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: Access Vector:
Attack Complexity: Access Complexity:
Privileges Required: Authentication:
User Interaction: Confidentiality:
Scope: Integrity:
Confidentiality: Availability:
Integrity:  
Availability:  
  
Reference:
FEDORA-2024-2ce1c754f7
FEDORA-2024-635a54eb7e
FEDORA-2024-be032e564d
FEDORA-2024-fd2569c4e9
https://lists.debian.org/debian-lts-announce/2024/05/msg00008.html
https://gitlab.gnome.org/GNOME/glib/-/issues/3268
https://security.netapp.com/advisory/ntap-20240531-0008/
https://www.openwall.com/lists/oss-security/2024/05/07/5

OVAL    11
oval:org.secpod.oval:def:613080
oval:org.secpod.oval:def:127735
oval:org.secpod.oval:def:127615
oval:org.secpod.oval:def:10000586
...
XCCDF    1

© SecPod Technologies