CVE-2018-16429
published 2018-09-04CVE-2018-16429: GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().
PriorityP434high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
3.53%
88.0th percentile
GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | glib2.0 | < glib2.0 2.58.0-1 (bookworm) | glib2.0 2.58.0-1 (bookworm) |
| gnome | glib | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x96r-v34q-q4vv: GNOME GLib 2
ghsa_unreviewed·2022-05-13
CVE-2018-16429 [HIGH] CWE-125 GHSA-x96r-v34q-q4vv: GNOME GLib 2
GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().
OSV
glib2.0 vulnerabilities
osv·2018-09-19·CVSS 9.8
CVE-2018-16428 [CRITICAL] glib2.0 vulnerabilities
glib2.0 vulnerabilities
It was discovered that GLib incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2018-16428)
It was discovered that GLib incorrectly handled certain files.
An attacker could possibly use this issue to access sensitive information.
(CVE-2018-16429)
OSV
CVE-2018-16429: GNOME GLib 2
osv·2018-09-04·CVSS 7.5
CVE-2018-16429 [HIGH] CVE-2018-16429: GNOME GLib 2
GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().
Ubuntu
GLib vulnerabilities
vendor_ubuntu·2018-09-19·CVSS 9.8
CVE-2018-16428 [CRITICAL] GLib vulnerabilities
Title: GLib vulnerabilities
Summary: Several security issues were fixed in GLib.
It was discovered that GLib incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2018-16428)
It was discovered that GLib incorrectly handled certain files.
An attacker could possibly use this issue to access sensitive information.
(CVE-2018-16429)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
GLib vulnerabilities
vendor_ubuntu·2018-09-19·CVSS 9.8
CVE-2018-16428 [CRITICAL] GLib vulnerabilities
Title: GLib vulnerabilities
Summary: Several security issues were fixed in GLib.
USN-3767-1 fixed a vulnerability in GLib. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that GLib incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2018-16428)
It was discovered that GLib incorrectly handled certain files.
An attacker could possibly use this issue to access sensitive information.
(CVE-2018-16429)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
glib2: Out-of-bounds read in g_markup_parse_context_parse() in gmarkup.c
vendor_redhat·2018-09-04·CVSS 7.5
CVE-2018-16429 [HIGH] CWE-125 glib2: Out-of-bounds read in g_markup_parse_context_parse() in gmarkup.c
glib2: Out-of-bounds read in g_markup_parse_context_parse() in gmarkup.c
GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().
Statement: The glib2 package in Red Hat Enterprise Linux 8 is not affected by this vulnerability because a newer and fixed version is shipped.
Mitigation: Since the only affected code in this flaw is g_markup_parse_context_parse(), any application (compiled with glib2) which does not use this function or any other function which calls this vulnerable code, is not affected by this flaw.
Package: firefox (Red Hat Enterprise Linux 5) - Will not fix
Package: glib2 (Red Hat Enterprise Linux 5) - Will not fix
Package: firefox (Red Hat Enterprise Linux 6) - Will not fix
Package: glib2 (Red H
Debian
CVE-2018-16429: glib2.0 - GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_cont...
vendor_debian·2018·CVSS 7.5
CVE-2018-16429 [HIGH] CVE-2018-16429: glib2.0 - GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_cont...
GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().
Scope: local
bookworm: resolved (fixed in 2.58.0-1)
bullseye: resolved (fixed in 2.58.0-1)
forky: resolved (fixed in 2.58.0-1)
sid: resolved (fixed in 2.58.0-1)
trixie: resolved (fixed in 2.58.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-16429 thunderbird: glib2: Out-of-bounds read in g_markup_parse_context_parse() in gmarkup.c [fedora-all]
bugzilla·2018-09-06·CVSS 7.5
CVE-2018-16429 [HIGH] CVE-2018-16429 thunderbird: glib2: Out-of-bounds read in g_markup_parse_context_parse() in gmarkup.c [fedora-all]
CVE-2018-16429 thunderbird: glib2: Out-of-bounds read in g_markup_parse_context_parse() in gmarkup.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2018-16429 glib2: Out-of-bounds read in g_markup_parse_context_parse() in gmarkup.c [fedora-all]
bugzilla·2018-09-06·CVSS 7.5
CVE-2018-16429 [HIGH] CVE-2018-16429 glib2: Out-of-bounds read in g_markup_parse_context_parse() in gmarkup.c [fedora-all]
CVE-2018-16429 glib2: Out-of-bounds read in g_markup_parse_context_parse() in gmarkup.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mult
Bugzilla
CVE-2018-16429 firefox: glib2: Out-of-bounds read in g_markup_parse_context_parse() in gmarkup.c [fedora-all]
bugzilla·2018-09-06·CVSS 7.5
CVE-2018-16429 [HIGH] CVE-2018-16429 firefox: glib2: Out-of-bounds read in g_markup_parse_context_parse() in gmarkup.c [fedora-all]
CVE-2018-16429 firefox: glib2: Out-of-bounds read in g_markup_parse_context_parse() in gmarkup.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
Bugzilla
CVE-2018-16429 chromium: glib2: Out-of-bounds read in g_markup_parse_context_parse() in gmarkup.c [fedora-all]
bugzilla·2018-09-06·CVSS 7.5
CVE-2018-16429 [HIGH] CVE-2018-16429 chromium: glib2: Out-of-bounds read in g_markup_parse_context_parse() in gmarkup.c [fedora-all]
CVE-2018-16429 chromium: glib2: Out-of-bounds read in g_markup_parse_context_parse() in gmarkup.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue af
Bugzilla
CVE-2018-16429 glib2: Out-of-bounds read in g_markup_parse_context_parse() in gmarkup.c
bugzilla·2018-09-06·CVSS 7.5
CVE-2018-16429 [HIGH] CVE-2018-16429 glib2: Out-of-bounds read in g_markup_parse_context_parse() in gmarkup.c
CVE-2018-16429 glib2: Out-of-bounds read in g_markup_parse_context_parse() in gmarkup.c
GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().
Upstream bug:
https://gitlab.gnome.org/GNOME/glib/issues/1361
Upstream patch:
https://gitlab.gnome.org/GNOME/glib/commit/cec71705406f0b2790422f0c1aa0ff3b4b464b1b
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1626173]
Created firefox tracking bugs for this issue:
Affects: fedora-all [bug 1626174]
Created glib2 tracking bugs for this issue:
Affects: fedora-all [bug 1626169]
Created thunderbird tracking bugs for this issue:
Affects: fedora-all [bug 1626176]
---
Mitigation:
Since the only affected code in this flaw is g_mar
https://gitlab.gnome.org/GNOME/glib/commit/cec71705406f0b2790422f0c1aa0ff3b4b464b1bhttps://gitlab.gnome.org/GNOME/glib/issues/1361https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2019/07/msg00029.htmlhttps://usn.ubuntu.com/3767-1/https://usn.ubuntu.com/3767-2/https://gitlab.gnome.org/GNOME/glib/commit/cec71705406f0b2790422f0c1aa0ff3b4b464b1bhttps://gitlab.gnome.org/GNOME/glib/issues/1361https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2019/07/msg00029.htmlhttps://usn.ubuntu.com/3767-1/https://usn.ubuntu.com/3767-2/
2018-09-04
Published