安全公告详情

NS-SA-2026-0061

2026-07-27 21:21:36

简介

moderate: gmp/glib2 security update

严重级别

moderate

主题

An update for gmp/glib2 is now available for NewStart CGSL MAIN 6.06.
NewStart Security has rated this update as having a security impact of moderate. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

gmp:
glib2:


Security Fix(es):
gmp: A flaw was found in gmp. An integer overflow vulnerability could allow an attacker to input an integer value leading to a crash. The highest threat from this vulnerability is to system availability.(CVE-2021-43618)
gmp: bugfix
glib2: file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used.(CVE-2019-12450)
glib2: No description is available for this CVE. (CVE-2023-24593)
glib2: GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity, even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.(CVE-2020-6750)
glib2: No description is available for this CVE. (CVE-2023-25180)
glib2: A flaw was found in GNOME GLib. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This issue could lead to the GDBus-based client behaving incorrectly with an application-dependent impact.(CVE-2024-34397)
glib2: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 6.06.11B10.

影响组件

  • gmp
  • glib2

影响产品

  • CGSL MAIN 6.06

更新包

{"fix":[{"product":"CGSL MAIN 6.06","pkgs":[{"binary":["gmp-6.2.0-13.0.1.zncgsl6.x86_64.rpm","gmp-devel-6.2.0-13.0.1.zncgsl6.x86_64.rpm","gmp-c++-6.2.0-13.0.1.zncgsl6.x86_64.rpm"],"source":"gmp-6.2.0-13.0.1.zncgsl6.src.rpm"},{"binary":["glib2-2.68.4-14.0.1.zncgsl6.t2.0.x86_64.rpm","glib2-devel-2.68.4-14.0.1.zncgsl6.t2.0.x86_64.rpm"],"source":"glib2-2.68.4-14.0.1.zncgsl6.t2.0.src.rpm"}]}]}

CVE

参考