NULL pointer dereference in Gnome GLib - CVE-2018-16428

 

NULL pointer dereference in Gnome GLib - CVE-2018-16428

Published: December 10, 2018


Vulnerability identifier: #VU16354
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-16428
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to cause DoS condition on the target system.

The vulnerability exists due to NULL pointer dereference in g_markup_parse_context_end_parse() in gmarkup.c. A local attacker can execute a specially crafted application or file that submits malicious input and cause the service to crash.


Affected software

Gnome GLib
Amazon Linux AMI
Opensuse
glib2
IBM Cloud Transformation Advisor
EMC ECS

How to mitigate CVE-2018-16428

Install update from vendor's website.

glib2 - update to 2.36.3-5.23
IBM Cloud Transformation Advisor - update to 3.4.0
EMC ECS - update to 3.5.0.1

External References

Related Security Bulletins