OESA-2024-1789

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-1789
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2024-1789.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2024-1789
Upstream
Published
2024-07-05T11:08:24Z
Modified
2025-08-12T05:43:57.426572Z
Summary
glib2 security update
Details

GLib is a bundle of three (formerly five) low-level system libraries written in C and developed mainly by GNOME. GLib's code was separated from GTK, so it can be used by software other than GNOME and has been developed in parallel ever since.

Security Fix(es):

An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.(CVE-2024-34397)

Database specific
{
    "severity": "Low"
}
References

Affected packages

openEuler:20.03-LTS-SP4 / glib2

Package

Name
glib2
Purl
pkg:rpm/openEuler/glib2&distro=openEuler-20.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.66.8-14.oe2003sp4

Ecosystem specific

{
    "aarch64": [
        "glib2-2.66.8-14.oe2003sp4.aarch64.rpm",
        "glib2-debuginfo-2.66.8-14.oe2003sp4.aarch64.rpm",
        "glib2-debugsource-2.66.8-14.oe2003sp4.aarch64.rpm",
        "glib2-devel-2.66.8-14.oe2003sp4.aarch64.rpm"
    ],
    "src": [
        "glib2-2.66.8-14.oe2003sp4.src.rpm"
    ],
    "noarch": [
        "glib2-help-2.66.8-14.oe2003sp4.noarch.rpm"
    ],
    "x86_64": [
        "glib2-2.66.8-14.oe2003sp4.x86_64.rpm",
        "glib2-debuginfo-2.66.8-14.oe2003sp4.x86_64.rpm",
        "glib2-debugsource-2.66.8-14.oe2003sp4.x86_64.rpm",
        "glib2-devel-2.66.8-14.oe2003sp4.x86_64.rpm"
    ]
}