CVE-2020-35457

NameCVE-2020-35457
DescriptionGNOME GLib before 2.65.3 has an integer overflow, that might lead to an out-of-bounds write, in g_option_group_add_entries. NOTE: the vendor's position is "Realistically this is not a security issue. The standard pattern is for callers to provide a static list of option entries in a fixed number of calls to g_option_group_add_entries()." The researcher states that this pattern is undocumented
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
glib2.0 (PTS)jessie, jessie (lts)2.42.1-1+deb8u7vulnerable
stretch (security)2.50.3-2+deb9u3vulnerable
stretch (lts), stretch2.50.3-2+deb9u6vulnerable
buster (security), buster, buster (lts)2.58.3-2+deb10u6vulnerable
bullseye2.66.8-1+deb11u4fixed
bullseye (security)2.66.8-1+deb11u3fixed
bookworm2.74.6-2+deb12u4fixed
bookworm (security)2.74.6-2+deb12u2fixed
trixie2.82.2-2fixed
sid2.82.2-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
glib2.0source(unstable)2.66.0-1unimportant

Notes

https://gitlab.gnome.org/GNOME/glib/-/commit/63c5b62f0a984fac9a9700b12f54fe878e016a5d
https://gitlab.gnome.org/GNOME/glib/-/issues/2197
Upstream position is that it is not realistically a security issue.

Search for package or bug name: Reporting problems