Out-of-bounds read in Gnome GLib - CVE-2018-16429
Published: September 4, 2018 / Updated: December 10, 2018
Vulnerability details
The vulnerability allows a local attacker to cause DoS condition on the target system.
The vulnerability exists due to out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str(). A local attacker can execute a specially crafted application or file that submits malicious input and cause the service to crash.
Affected software
Amazon Linux AMI
Opensuse
Dynamic System Analysis (DSA) Preboot
Flex System Chassis Management Module (CMM)
glib2
How to mitigate CVE-2018-16429
Flex System Chassis Management Module (CMM) - update to 2pet18c-2.5.16c
glib2 - addressed in versions 2.36.3-5.23, 2.36.3-5.24