Wind River Support Network

HomeDefectsLIN10-5647
Fixed

LIN10-5647 : Security Advisory - glib-2.0 - CVE-2019-9633

Created: Mar 27, 2019    Updated: May 13, 2022
Resolved Date: Apr 3, 2019
Found In Version: 10.17.41.15
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace

Description

gio/gsocketclient.c in GNOME GLib 2.59.2 does not ensure that a parent GTask remains alive during the execution of a connection-attempting enumeration, which allows remote attackers to cause a denial of service (g_socket_client_connected_callback mishandling and application crash) via a crafted web site, as demonstrated by GNOME Web (aka Epiphany).

CREATE(Triage): {Link=https://nvd.nist.gov/vuln/detail/CVE-2019-9633 User=admin}

CVEs


Live chat
Online