You are here
Home > Preporuke > Sigurnosni nedostatak programske biblioteke glib2.0

Sigurnosni nedostatak programske biblioteke glib2.0

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-4049-3
August 05, 2019

glib2.0 regression
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 16.04 LTS

Summary:

USN-4049-1 introduced a regression in GLib.

Software Description:
– glib2.0: GLib Input, Output and Streaming Library (fam module)

Details:

USN-4049-1 fixed a vulnerability in GLib. The update introduced a regression
in Ubuntu 16.04 LTS causing a possibly memory leak. This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

It was discovered that GLib created directories and files without properly
restricting permissions. An attacker could possibly use this issue to access
sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
libglib2.0-0 2.48.2-0ubuntu4.4
libglib2.0-bin 2.48.2-0ubuntu4.4

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4049-3
https://usn.ubuntu.com/4049-1
https://launchpad.net/bugs/1838890

Package Information:
https://launchpad.net/ubuntu/+source/glib2.0/2.48.2-0ubuntu4.4
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1

iQIcBAEBAgAGBQJdSIeZAAoJEEW851uECx9pCK4P+QF6+rGbhIMFkh96UVW8v5kZ
8miB3AUf56ZjW0xB5+oR1l6wh2CW5PkZJB0ofs70tVCU3timsmEbn/ggr4S/3Vcg
UP7/R4m1FLphCWDGAbw+6AjlhZo+05D9ZhpazW5wcsgQ0YWfZfd0c0PN8+Kw7TnC
DYD9jCGtufGSoHvcZsGByENm6dfA13VVVybXaj2Z6L4m1+Jrg31TFUK7ycedPnlG
AMV3PbRf8z2+WIqXhKFCpWSTC7zc3ZULrZVw4KwDjmq8a2G/G/E00o9FWz2RXhIU
jErACSpfXYlXLo83IHvLigHfLE/wMfTCS3ZAMGH3H6PTe/idmfIb6oV7EkTf/HJ3
Dx4CbYsTdH5X0dBCCznbwxOcEE5cf0yi4jvjXF64+WB22FcMKSz3u+fN2PV+TeRi
G58c6J5dKb8UqzNOK1TJQY08+yUnp0WUU4LyQo63uibnmNyy2/4/WLkwVYv2FGPJ
y/5DxHvk95hQTv004/DzhLrukDLEcEbqHjsn73Yar+pFioh4AfJnWkilmYo/3xJQ
sxlg6G/8eOyx6ingDIBdhehteke5xkZRhgxS4sbutdRCK+V3pizehQGvYO3r0EhO
iV6bb/F7ByaYFJ6WhHd5n2eb3wxDFBYLof7eVOORoCGVIAHe6VMfOCFj35FVug9g
Uou081S3wbgejgTIFHXf
=769c
—–END PGP SIGNATURE—–

AutorZvonimir Bosnjak
Cert idNCERT-REF-2019-08-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostatak programskog paketa bash

Otkriven je sigurnosni nedostatak u programskom paketu bash za operacijski sustav Ubuntu. Otkriveni nedostatak potencijalnim napadačima omogućuje izvršavanje proizvoljnog programskog...

Close