Heap-based buffer overflow in Gnome GLib - CVE-2023-32643

 

Heap-based buffer overflow in Gnome GLib - CVE-2023-32643

Published: June 15, 2023


Vulnerability identifier: #VU77352
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32643
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the g_variant_serialised_get_child() function. A remote attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Gnome GLib
Isolation Segment
VMware Tanzu Application Service for VMs
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE CaaS Platform
SUSE Enterprise Storage
Oracle Solaris
Ubuntu
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
Fedora
LANTIME Operating System Firmware (LTOS)
libglib2.0-bin (Ubuntu package)
libglib2.0-0 (Ubuntu package)
libglib-2_0-0-32bit
glib2-lang
glib2-tools-debuginfo
libgio-2_0-0-debuginfo
libglib-2_0-0-debuginfo
glib2-debugsource
libgthread-2_0-0-debuginfo
libgobject-2_0-0-debuginfo
libgobject-2_0-0
libgmodule-2_0-0-debuginfo
glib2-devel
glib2-tools
glib2-devel-debuginfo
libgmodule-2_0-0
libgio-2_0-0
libglib-2_0-0
libgthread-2_0-0
libgmodule-2_0-0-32bit-debuginfo
libgobject-2_0-0-32bit
libgio-2_0-0-32bit-debuginfo
libgmodule-2_0-0-32bit
libgio-2_0-0-32bit
libglib-2_0-0-32bit-debuginfo
libgobject-2_0-0-32bit-debuginfo
mingw-glib2
VMware Tanzu Operations Manager
Platform Automation Toolkit
IBM CICS TX Advanced

How to mitigate CVE-2023-32643

Install updates from vendor's website.

Gnome GLib - addressed in versions 2.74.4, 2.75.1
Isolation Segment - addressed in versions 3.0.20, 4.0.12
VMware Tanzu Application Service for VMs - addressed in versions 3.0.20, 4.0.12
LANTIME Operating System Firmware (LTOS) - update to 7.08.007
libglib2.0-bin (Ubuntu package) - addressed in versions Ubuntu Pro, 2.64.6-1~ubuntu20.04.6, 2.72.4-0ubuntu2.2, 2.74.3-0ubuntu1.2
libglib2.0-0 (Ubuntu package) - addressed in versions Ubuntu Pro, 2.64.6-1~ubuntu20.04.6, 2.72.4-0ubuntu2.2, 2.74.3-0ubuntu1.2
VMware Tanzu Operations Manager - addressed in versions 2.10.65, 3.0.12
libglib-2_0-0-32bit - update to 2.54.3-150000.4.29.1
glib2-lang - update to 2.54.3-150000.4.29.1
glib2-tools-debuginfo - update to 2.54.3-150000.4.29.1
libgio-2_0-0-debuginfo - update to 2.54.3-150000.4.29.1
libglib-2_0-0-debuginfo - update to 2.54.3-150000.4.29.1
glib2-debugsource - update to 2.54.3-150000.4.29.1
libgthread-2_0-0-debuginfo - update to 2.54.3-150000.4.29.1
libgobject-2_0-0-debuginfo - update to 2.54.3-150000.4.29.1
libgobject-2_0-0 - update to 2.54.3-150000.4.29.1
libgmodule-2_0-0-debuginfo - update to 2.54.3-150000.4.29.1
glib2-devel - update to 2.54.3-150000.4.29.1
glib2-tools - update to 2.54.3-150000.4.29.1
glib2-devel-debuginfo - update to 2.54.3-150000.4.29.1
libgmodule-2_0-0 - update to 2.54.3-150000.4.29.1
libgio-2_0-0 - update to 2.54.3-150000.4.29.1
libglib-2_0-0 - update to 2.54.3-150000.4.29.1
libgthread-2_0-0 - update to 2.54.3-150000.4.29.1
libgmodule-2_0-0-32bit-debuginfo - update to 2.54.3-150000.4.29.1
libgobject-2_0-0-32bit - update to 2.54.3-150000.4.29.1
libgio-2_0-0-32bit-debuginfo - update to 2.54.3-150000.4.29.1
libgmodule-2_0-0-32bit - update to 2.54.3-150000.4.29.1
libgio-2_0-0-32bit - update to 2.54.3-150000.4.29.1
libglib-2_0-0-32bit-debuginfo - update to 2.54.3-150000.4.29.1
libgobject-2_0-0-32bit-debuginfo - update to 2.54.3-150000.4.29.1
mingw-glib2 - addressed in versions 2.74.7-1.fc37, 2.74.7-1.fc38
Platform Automation Toolkit - addressed in versions 4.4.19, 4.4.32, 5.0.0, 5.0.25, 5.1.0, 5.1.2
IBM CICS TX Advanced - update to 10.1.0.0 ifix21

External References

Related Security Bulletins