NULL pointer dereference in Gnome GLib - CVE-2018-16428
Published: December 10, 2018
Vulnerability details
The vulnerability allows a local attacker to cause DoS condition on the target system.
The vulnerability exists due to NULL pointer dereference in g_markup_parse_context_end_parse() in gmarkup.c. A local attacker can execute a specially crafted application or file that submits malicious input and cause the service to crash.
Affected software
Amazon Linux AMI
Opensuse
glib2
IBM Cloud Transformation Advisor
EMC ECS
How to mitigate CVE-2018-16428
IBM Cloud Transformation Advisor - update to 3.4.0
EMC ECS - update to 3.5.0.1