Bug 2156440 (CVE-2019-25085)
Summary: | CVE-2019-25085 gvdb: use after free issue was fixed in gvdb_table_write_contents_async() | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Sandipan Roy <saroy> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED NOTABUG | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | mcatanza, mkasik |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: |
A vulnerability was found in GNOME gvdb. This issue affects the gvdb_table_write_contents_async function of the gvdb-builder.c. file. The manipulation leads to a use—after—free vulnerability where it is possible to initiate the attack remotely.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2023-01-07 05:30:37 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2156441, 2156442, 2156443, 2156458, 2156459, 2156460, 2156461 | ||
Bug Blocks: | 2156323 |
Description
Sandipan Roy
2022-12-27 04:24:59 UTC
Created epiphany tracking bugs for this issue: Affects: fedora-36 [bug 2156441] Created glib2 tracking bugs for this issue: Affects: fedora-36 [bug 2156442] Affects: fedora-37 [bug 2156443] Note this vulnerability was only present in gvdb for six days, and no version of glib or dconf is affected, so users don't need to worry about this. I believe Epiphany is the only software that was actually impacted (and it was fixed there before it made its way into any release). This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-25085 |