Oval Definition:oval:com.redhat.rhsa:def:20090336
Revision Date:2009-03-24Version:639
Title:RHSA-2009:0336: glib2 security update (Moderate)
Description:GLib is the low-level core library that forms the basis for projects such as GTK+ and GNOME. It provides data structure handling for C, portability wrappers, and interfaces for such runtime functionality as an event loop, threads, dynamic loading, and an object system.

  • Diego Pettenò discovered multiple integer overflows causing heap-based buffer overflows in GLib's Base64 encoding and decoding functions. An attacker could use these flaws to crash an application using GLib's Base64 functions to encode or decode large, untrusted inputs, or, possibly, execute arbitrary code as the user running the application. (CVE-2008-4316)

    Note: No application shipped with Red Hat Enterprise Linux 5 uses the affected functions. Third-party applications may, however, be affected.

    All users of glib2 should upgrade to these updated packages, which contain backported patches to resolve these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2008-4316
    RHSA-2009:0336
    RHSA-2009:0336-01
    RHSA-2009:0336-01
    Platform(s):Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • glib2 is earlier than 0:2.12.3-4.el5_3.1
  • AND glib2 is signed with Red Hat redhatrelease2 key
  • glib2-devel is earlier than 0:2.12.3-4.el5_3.1
  • AND glib2-devel is signed with Red Hat redhatrelease2 key
  • BACK