CVE-2018-16428
published 2018-09-04CVE-2018-16428: In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference.
PriorityP338critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.69%
90.8th percentile
In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | glib2.0 | < glib2.0 2.58.0-1 (bookworm) | glib2.0 2.58.0-1 (bookworm) |
| gnome | glib | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wj6v-2jfm-gw75: In GNOME GLib 2
ghsa_unreviewed·2022-05-14
CVE-2018-16428 [CRITICAL] CWE-476 GHSA-wj6v-2jfm-gw75: In GNOME GLib 2
In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference.
OSV
glib2.0 vulnerabilities
osv·2018-09-19·CVSS 9.8
CVE-2018-16428 [CRITICAL] glib2.0 vulnerabilities
glib2.0 vulnerabilities
It was discovered that GLib incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2018-16428)
It was discovered that GLib incorrectly handled certain files.
An attacker could possibly use this issue to access sensitive information.
(CVE-2018-16429)
OSV
CVE-2018-16428: In GNOME GLib 2
osv·2018-09-04·CVSS 9.8
CVE-2018-16428 [CRITICAL] CVE-2018-16428: In GNOME GLib 2
In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference.
Ubuntu
GLib vulnerabilities
vendor_ubuntu·2018-09-19·CVSS 9.8
CVE-2018-16428 [CRITICAL] GLib vulnerabilities
Title: GLib vulnerabilities
Summary: Several security issues were fixed in GLib.
It was discovered that GLib incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2018-16428)
It was discovered that GLib incorrectly handled certain files.
An attacker could possibly use this issue to access sensitive information.
(CVE-2018-16429)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
GLib vulnerabilities
vendor_ubuntu·2018-09-19·CVSS 9.8
CVE-2018-16428 [CRITICAL] GLib vulnerabilities
Title: GLib vulnerabilities
Summary: Several security issues were fixed in GLib.
USN-3767-1 fixed a vulnerability in GLib. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that GLib incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2018-16428)
It was discovered that GLib incorrectly handled certain files.
An attacker could possibly use this issue to access sensitive information.
(CVE-2018-16429)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
glib2: NULL pointer dereference in g_markup_parse_context_end_parse() function in gmarkup.c
vendor_redhat·2018-09-04·CVSS 9.8
CVE-2018-16428 [CRITICAL] CWE-119 glib2: NULL pointer dereference in g_markup_parse_context_end_parse() function in gmarkup.c
glib2: NULL pointer dereference in g_markup_parse_context_end_parse() function in gmarkup.c
In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference.
Mitigation: Since the only affected code in this flaw is g_markup_parse_context_end_parse(), any application (compiled with glib2) which does not use this function or any other function which calls this vulnerable code, is not affected by this flaw.
Package: firefox (Red Hat Enterprise Linux 5) - Will not fix
Package: glib2 (Red Hat Enterprise Linux 5) - Will not fix
Package: firefox (Red Hat Enterprise Linux 6) - Will not fix
Package: glib2 (Red Hat Enterprise Linux 6) - Will not fix
Package: thunderbird (Red Hat Enterprise Linux 6) - Will not fix
Package: firefox (Red Hat Enterprise Linux
Debian
CVE-2018-16428: glib2.0 - In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL...
vendor_debian·2018·CVSS 9.8
CVE-2018-16428 [CRITICAL] CVE-2018-16428: glib2.0 - In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL...
In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference.
Scope: local
bookworm: resolved (fixed in 2.58.0-1)
bullseye: resolved (fixed in 2.58.0-1)
forky: resolved (fixed in 2.58.0-1)
sid: resolved (fixed in 2.58.0-1)
trixie: resolved (fixed in 2.58.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-16428 thunderbird: glib2: NULL pointer dereference in g_markup_parse_context_end_parse() function in gmarkup.c [fedora-all]
bugzilla·2018-09-06·CVSS 9.8
CVE-2018-16428 [CRITICAL] CVE-2018-16428 thunderbird: glib2: NULL pointer dereference in g_markup_parse_context_end_parse() function in gmarkup.c [fedora-all]
CVE-2018-16428 thunderbird: glib2: NULL pointer dereference in g_markup_parse_context_end_parse() function in gmarkup.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message
Bugzilla
CVE-2018-16428 chromium: glib2: NULL pointer dereference in g_markup_parse_context_end_parse() function in gmarkup.c [fedora-all]
bugzilla·2018-09-06·CVSS 9.8
CVE-2018-16428 [CRITICAL] CVE-2018-16428 chromium: glib2: NULL pointer dereference in g_markup_parse_context_end_parse() function in gmarkup.c [fedora-all]
CVE-2018-16428 chromium: glib2: NULL pointer dereference in g_markup_parse_context_end_parse() function in gmarkup.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2018-16428 firefox: glib2: NULL pointer dereference in g_markup_parse_context_end_parse() function in gmarkup.c [fedora-all]
bugzilla·2018-09-06·CVSS 9.8
CVE-2018-16428 [CRITICAL] CVE-2018-16428 firefox: glib2: NULL pointer dereference in g_markup_parse_context_end_parse() function in gmarkup.c [fedora-all]
CVE-2018-16428 firefox: glib2: NULL pointer dereference in g_markup_parse_context_end_parse() function in gmarkup.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
N
Bugzilla
CVE-2018-16428 glib2: NULL pointer dereference in g_markup_parse_context_end_parse() function in gmarkup.c [fedora-all]
bugzilla·2018-09-06·CVSS 9.8
CVE-2018-16428 [CRITICAL] CVE-2018-16428 glib2: NULL pointer dereference in g_markup_parse_context_end_parse() function in gmarkup.c [fedora-all]
CVE-2018-16428 glib2: NULL pointer dereference in g_markup_parse_context_end_parse() function in gmarkup.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2018-16428 glib2: NULL pointer dereference in g_markup_parse_context_end_parse() function in gmarkup.c
bugzilla·2018-09-06·CVSS 9.8
CVE-2018-16428 [CRITICAL] CVE-2018-16428 glib2: NULL pointer dereference in g_markup_parse_context_end_parse() function in gmarkup.c
CVE-2018-16428 glib2: NULL pointer dereference in g_markup_parse_context_end_parse() function in gmarkup.c
In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() function in gmarkup.c has a NULL pointer dereference.
Upstream bug:
https://gitlab.gnome.org/GNOME/glib/issues/1364
Upstream patch:
https://gitlab.gnome.org/GNOME/glib/commit/fccef3cc822af74699cca84cd202719ae61ca3b9
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1626164]
Created firefox tracking bugs for this issue:
Affects: fedora-all [bug 1626165]
Created glib2 tracking bugs for this issue:
Affects: fedora-all [bug 1626162]
Created thunderbird tracking bugs for this issue:
Affects: fedora-all [bug 1626167]
---
Mitigation:
Since the only affected code in this flaw is g_ma
http://www.openwall.com/lists/oss-security/2020/02/14/3http://www.securityfocus.com/bid/105210https://gitlab.gnome.org/GNOME/glib/commit/fccef3cc822af74699cca84cd202719ae61ca3b9https://gitlab.gnome.org/GNOME/glib/issues/1364https://lists.debian.org/debian-lts-announce/2019/07/msg00029.htmlhttps://usn.ubuntu.com/3767-1/https://usn.ubuntu.com/3767-2/http://www.openwall.com/lists/oss-security/2020/02/14/3http://www.securityfocus.com/bid/105210https://gitlab.gnome.org/GNOME/glib/commit/fccef3cc822af74699cca84cd202719ae61ca3b9https://gitlab.gnome.org/GNOME/glib/issues/1364https://lists.debian.org/debian-lts-announce/2019/07/msg00029.htmlhttps://usn.ubuntu.com/3767-1/https://usn.ubuntu.com/3767-2/
2018-09-04
Published