CVE-2024-34397
published 2024-05-07CVE-2024-34397: An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system…
PriorityP423medium5.2CVSS 3.1
AVPACLPRNUINSUCNIHAL
EPSS
0.76%
51.0th percentile
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | glib2.0 | < glib2.0 2.74.6-2+deb12u1 (bookworm) | glib2.0 2.74.6-2+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnome | glib | < 2.78.5 | 2.78.5 |
| gnome | glib | >= 2.79.0 < 2.80.1 | 2.80.1 |
| msrc | azl3_glib_2.78.1-5_on_azure_linux_3.0 | — | — |
| msrc | azl3_glib_2.78.6-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_glib_2.71.0-5_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_glib_2.71.0-6_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_glib_2.71.0-7_on_cbl_mariner_2.0 | — | — |
| netapp | ontap_tools | — | — |
CVSS provenance
nvdv3.15.2MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
osv5.2MEDIUM
vendor_debian5.2MEDIUM
vendor_msrc5.2MEDIUM
vendor_redhat5.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU Family
cisa_ics·2025-06-12
Siemens SIMATIC S7-1500 CPU Family
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU Family
Release DateJune 12, 2025
Alert CodeICSA-25-162-05
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU family
- Vulnerabilities: Missing Encryption of Sensitive Data, Out-of-bounds Read, Use After Free, Stack-
Microsoft
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shar
vendor_msrc·2024-05-14·CVSS 5.2
CVE-2024-34397 [MEDIUM] CWE-290 An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shar
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of
Ubuntu
GLib vulnerability
vendor_ubuntu·2024-05-09
CVE-2024-34397 GLib vulnerability
Title: GLib vulnerability
Summary: GLib could be made to accept spoofed D-Bus signals.
Alicia Boya García discovered that GLib incorrectly handled signal
subscriptions. A local attacker could use this issue to spoof D-Bus signals
resulting in a variety of impacts including possible privilege escalation.
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Red Hat
glib2: Signal subscription vulnerabilities
vendor_redhat·2024-05-07·CVSS 5.2
CVE-2024-34397 [MEDIUM] CWE-940 glib2: Signal subscription vulnerabilities
glib2: Signal subscription vulnerabilities
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.
A flaw was found in GNOME GLib. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as h
Debian
CVE-2024-34397: glib2.0 - An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x befor...
vendor_debian·2024·CVSS 5.2
CVE-2024-34397 [MEDIUM] CVE-2024-34397: glib2.0 - An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x befor...
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.
Scope: local
bookworm: resolved (fixed in 2.74.6-2+deb12u1)
bullseye: resolved (fixed in 2.66.8-1+deb11u2)
forky: resolved (fixed in 2.80.0-10)
sid: resolved (fixed in 2.80.0-10)
trixie: resolved (fixed in 2.80.0-10)
GHSA
GHSA-f632-c3rh-r2v2: An issue was discovered in GNOME GLib before 2
ghsa_unreviewed·2024-05-07
CVE-2024-34397 [MEDIUM] CWE-290 GHSA-f632-c3rh-r2v2: An issue was discovered in GNOME GLib before 2
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.
OSV
CVE-2024-34397: An issue was discovered in GNOME GLib before 2
osv·2024-05-07·CVSS 5.2
CVE-2024-34397 [MEDIUM] CVE-2024-34397: An issue was discovered in GNOME GLib before 2
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.
No detection rules found.
No public exploits indexed.
https://gitlab.gnome.org/GNOME/glib/-/issues/3268https://lists.debian.org/debian-lts-announce/2024/05/msg00008.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IRSFYAE5X23TNRWX7ZWEJOMISLCDSYNS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LCDY3KA7G7D3DRXYTT46K6LFHS2KHWBH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LL6HSJDXCXMLEIJBYV6CPOR4K2NTCTXW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UNFJHISR4O6VFOHBFWH5I5WWMG37H63A/https://security.netapp.com/advisory/ntap-20240531-0008/https://www.openwall.com/lists/oss-security/2024/05/07/5https://gitlab.gnome.org/GNOME/glib/-/issues/3268https://lists.debian.org/debian-lts-announce/2024/05/msg00008.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IRSFYAE5X23TNRWX7ZWEJOMISLCDSYNS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LCDY3KA7G7D3DRXYTT46K6LFHS2KHWBH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LL6HSJDXCXMLEIJBYV6CPOR4K2NTCTXW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UNFJHISR4O6VFOHBFWH5I5WWMG37H63A/https://lists.fedoraproject.org/archives/list/[email protected]/message/IRSFYAE5X23TNRWX7ZWEJOMISLCDSYNS/https://lists.fedoraproject.org/archives/list/[email protected]/message/LCDY3KA7G7D3DRXYTT46K6LFHS2KHWBH/https://lists.fedoraproject.org/archives/list/[email protected]/message/LL6HSJDXCXMLEIJBYV6CPOR4K2NTCTXW/https://lists.fedoraproject.org/archives/list/[email protected]/message/UNFJHISR4O6VFOHBFWH5I5WWMG37H63A/https://security.netapp.com/advisory/ntap-20240531-0008/https://www.openwall.com/lists/oss-security/2024/05/07/5https://cert-portal.siemens.com/productcert/html/ssa-082556.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-613116.html
2024-05-07
Published