Out-of-bounds read in Gnome GLib - CVE-2018-16429

 

Out-of-bounds read in Gnome GLib - CVE-2018-16429

Published: September 4, 2018 / Updated: December 10, 2018


Vulnerability identifier: #VU14608
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-16429
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to cause DoS condition on the target system.

The vulnerability exists due to out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str(). A local attacker can execute a specially crafted application or file that submits malicious input and cause the service to crash.


Affected software

Gnome GLib
Amazon Linux AMI
Opensuse
Dynamic System Analysis (DSA) Preboot
Flex System Chassis Management Module (CMM)
glib2

How to mitigate CVE-2018-16429

Install update from vendor's website.

Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
Flex System Chassis Management Module (CMM) - update to 2pet18c-2.5.16c
glib2 - addressed in versions 2.36.3-5.23, 2.36.3-5.24

External References

Related Security Bulletins