cbcvebase.
CVE-2021-3800
published 2022-08-23

CVE-2021-3800: A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivileged ones…

PriorityP422medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.53%
41.3th percentile
A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivileged ones under the right condition.

Affected

6 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianglib2.0< glib2.0 2.64.0-1 (bookworm)glib2.0 2.64.0-1 (bookworm)
gnomeglib< 2.62.52.62.5
gnomeglib
gnomeglib>= 2.63.0 < 2.63.62.63.6
msrccm1_glib_2.58.0-10_on_cbl_mariner_1.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.