Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-32643
HistoryJun 07, 2023 - 12:00 a.m.

CVE-2023-32643

2023-06-0700:00:00
ubuntu.com
ubuntu.com
18
glib
gvariant deserialization code
buffer overflow
vulnerability
fix
distributors
backport
cve-2023-32665

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

40.2%

A flaw was found in GLib. The GVariant deserialization code is vulnerable
to a heap buffer overflow introduced by the fix for CVE-2023-32665. This
bug does not affect any released version of GLib, but does affect GLib
distributors who followed the guidance of GLib developers to backport the
initial fix for CVE-2023-32665.

Bugs

Notes

Author Note
mdeslaur same fixes as CVE-2023-32636
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchglib2.0< 2.56.4-0ubuntu0.18.04.9+esm3UNKNOWN
ubuntu20.04noarchglib2.0< 2.64.6-1~ubuntu20.04.6UNKNOWN
ubuntu22.04noarchglib2.0< 2.72.4-0ubuntu2.2UNKNOWN
ubuntu22.10noarchglib2.0< 2.74.3-0ubuntu1.2UNKNOWN
ubuntu14.04noarchglib2.0< 2.40.2-0ubuntu1.1+esm6UNKNOWN
ubuntu16.04noarchglib2.0< 2.48.2-0ubuntu4.8+esm3UNKNOWN

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

40.2%