CVE-2021-28153
published 2021-03-11CVE-2021-28153: An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
2.62%
83.8th percentile
An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is attacker-controlled. (If the path is a symlink to a file that already exists, then the contents of that file correctly remain unchanged.)
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | glib2.0 | < glib2.0 2.66.7-2 (bookworm) | glib2.0 2.66.7-2 (bookworm) |
| fedoraproject | fedora | — | — |
| gnome | glib | < 2.66.8 | 2.66.8 |
| msrc | cbl2_glib_2.60.1-5_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GLib vulnerability
vendor_ubuntu·2021-03-15
CVE-2021-28153 GLib vulnerability
Title: GLib vulnerability
Summary: GLib could be made to create files if it opened a specially crafted
archive.
It was discovered that GLib incorrectly handled certain symlinks when
replacing files. If a user or automated system were tricked into extracting
a specially crafted file with File Roller, a remote attacker could possibly
create files outside of the intended directory.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
glib: g_file_replace() with G_FILE_CREATE_REPLACE_DESTINATION creates empty target for dangling symlink
vendor_redhat·2021-03-10·CVSS 5.3
CVE-2021-28153 [MEDIUM] CWE-59 glib: g_file_replace() with G_FILE_CREATE_REPLACE_DESTINATION creates empty target for dangling symlink
glib: g_file_replace() with G_FILE_CREATE_REPLACE_DESTINATION creates empty target for dangling symlink
An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is attacker-controlled. (If the path is a symlink to a file that already exists, then the contents of that file correctly remain unchanged.)
Package: firefox (Red Hat Enterprise Linux 6) - Out of support scope
Package: glib2 (Red Hat Enterprise Linux 6) - Out of support scope
Package: thunderbird (Red Hat Enterprise Linux 6) - Out of support scope
Package: glib2 (Red Hat Enterprise Lin
Microsoft
An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink it incorrectly also creates the t
vendor_msrc·2021-03-09·CVSS 5.3
CVE-2021-28153 [MEDIUM] CWE-59 An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink it incorrectly also creates the t
An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink it incorrectly also creates the target of the symlink as an empty file which could conceivably have security relevance if the symlink is attacker-controlled. (If the path is a symlink to a file that already exists then the contents of that file correctly remain unchanged.)
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which th
Debian
CVE-2021-28153: glib2.0 - An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is us...
vendor_debian·2021·CVSS 5.3
CVE-2021-28153 [MEDIUM] CVE-2021-28153: glib2.0 - An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is us...
An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is attacker-controlled. (If the path is a symlink to a file that already exists, then the contents of that file correctly remain unchanged.)
Scope: local
bookworm: resolved (fixed in 2.66.7-2)
bullseye: resolved (fixed in 2.66.7-2)
forky: resolved (fixed in 2.66.7-2)
sid: resolved (fixed in 2.66.7-2)
trixie: resolved (fixed in 2.66.7-2)
GHSA
GHSA-9hh6-p5c5-mmmf: An issue was discovered in GNOME GLib before 2
ghsa_unreviewed·2022-05-24
CVE-2021-28153 [MEDIUM] CWE-59 GHSA-9hh6-p5c5-mmmf: An issue was discovered in GNOME GLib before 2
An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is attacker-controlled. (If the path is a symlink to a file that already exists, then the contents of that file correctly remain unchanged.)
OSV
CVE-2021-28153: An issue was discovered in GNOME GLib before 2
osv·2021-03-11·CVSS 5.3
CVE-2021-28153 [MEDIUM] CVE-2021-28153: An issue was discovered in GNOME GLib before 2
An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is attacker-controlled. (If the path is a symlink to a file that already exists, then the contents of that file correctly remain unchanged.)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gitlab.gnome.org/GNOME/glib/-/issues/2325https://lists.debian.org/debian-lts-announce/2022/06/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6RXTD5HCP2K4AAUSWWZTBKQNHRCTAEOF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ICUTQPHZNZWX2DZR46QFLQZRHVMHIILJ/https://security.gentoo.org/glsa/202107-13https://security.netapp.com/advisory/ntap-20210416-0003/https://gitlab.gnome.org/GNOME/glib/-/issues/2325https://lists.debian.org/debian-lts-announce/2022/06/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6RXTD5HCP2K4AAUSWWZTBKQNHRCTAEOF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ICUTQPHZNZWX2DZR46QFLQZRHVMHIILJ/https://security.gentoo.org/glsa/202107-13https://security.netapp.com/advisory/ntap-20210416-0003/
2021-03-11
Published