CVE-2020-35457Integer Overflow or Wraparound in Glib

Severity
7.8HIGHNVD
EPSS
0.2%
top 59.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 14
Latest updateMay 24

Description

GNOME GLib before 2.65.3 has an integer overflow, that might lead to an out-of-bounds write, in g_option_group_add_entries. NOTE: the vendor's position is "Realistically this is not a security issue. The standard pattern is for callers to provide a static list of option entries in a fixed number of calls to g_option_group_add_entries()." The researcher states that this pattern is undocumented

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

NVDgnome/glib< 2.65.3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-2fcx-98cm-5x99: ** DISPUTED ** GNOME GLib before 22022-05-24
OSV
CVE-2020-35457: GNOME GLib before 22020-12-14
CVEList
CVE-2020-35457: GNOME GLib before 22020-12-14

📋Vendor Advisories

2
Microsoft
GNOME GLib before 2.65.3 has an integer overflow that might lead to an out-of-bounds write in g_option_group_add_entries. NOTE: the vendor's position is "Realistically this is not a security issue. Th2020-12-08
Debian
CVE-2020-35457: glib2.0 - GNOME GLib before 2.65.3 has an integer overflow, that might lead to an out-of-b...2020
CVE-2020-35457 — Integer Overflow or Wraparound in Glib | cvebase