CVE-2021-28153

Description

An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is attacker-controlled. (If the path is a symlink to a file that already exists, then the contents of that file correctly remain unchanged.)

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS Score
Exploitation Probability
0.574

Associated Vulnerability

VulnerabilityOS Platform
GLib library of C routines (USN-4764-1) libglib2.0-0_2.48.2-0ubuntu4.8_i386.debLinux
GLib library of C routines (USN-4764-1) libglib2.0-0_2.48.2-0ubuntu4.8_amd64.debLinux
GLib library of C routines (USN-4764-1) libglib2.0-0_2.66.1-2ubuntu0.2_i386.debLinux
GLib library of C routines (USN-4764-1) libglib2.0-0_2.66.1-2ubuntu0.2_amd64.debLinux
GLib library of C routines (USN-4764-1) libglib2.0-0_2.64.6-1~ubuntu20.04.3_i386.debLinux
GLib library of C routines (USN-4764-1) libglib2.0-0_2.64.6-1~ubuntu20.04.3_amd64.debLinux
GLib library of C routines (USN-4764-1) libglib2.0-0_2.56.4-0ubuntu0.18.04.8_i386.debLinux
GLib library of C routines (USN-4764-1) libglib2.0-0_2.56.4-0ubuntu0.18.04.8_amd64.debLinux
SUSE-SU-2022:1758-1(SUSE Linux Enterprise Server 12-SP5 ) glib2-debugsource-2.48.2-12.28.1.x86_64.rpmLinux
SUSE-SU-2022:1758-1(SUSE Linux Enterprise Server 12-SP5 ) glib2-lang-2.48.2-12.28.1.noarch.rpmLinux
SUSE-SU-2022:1758-1(SUSE Linux Enterprise Server 12-SP5 ) glib2-tools-2.48.2-12.28.1.x86_64.rpmLinux
SUSE-SU-2022:1758-1(SUSE Linux Enterprise Server 12-SP5 ) glib2-tools-debuginfo-2.48.2-12.28.1.x86_64.rpmLinux
SUSE-SU-2022:1758-1(SUSE Linux Enterprise Server 12-SP5 ) libgio-2_0-0-2.48.2-12.28.1.x86_64.rpmLinux
SUSE-SU-2022:1758-1(SUSE Linux Enterprise Server 12-SP5 ) libgio-2_0-0-32bit-2.48.2-12.28.1.x86_64.rpmLinux
SUSE-SU-2022:1758-1(SUSE Linux Enterprise Server 12-SP5 ) libgio-2_0-0-debuginfo-2.48.2-12.28.1.x86_64.rpmLinux
SUSE-SU-2022:1758-1(SUSE Linux Enterprise Server 12-SP5 ) libgio-2_0-0-debuginfo-32bit-2.48.2-12.28.1.x86_64.rpmLinux
SUSE-SU-2022:1758-1(SUSE Linux Enterprise Server 12-SP5 ) libglib-2_0-0-2.48.2-12.28.1.x86_64.rpmLinux
SUSE-SU-2022:1758-1(SUSE Linux Enterprise Server 12-SP5 ) libglib-2_0-0-32bit-2.48.2-12.28.1.x86_64.rpmLinux
SUSE-SU-2022:1758-1(SUSE Linux Enterprise Server 12-SP5 ) libglib-2_0-0-debuginfo-2.48.2-12.28.1.x86_64.rpmLinux
SUSE-SU-2022:1758-1(SUSE Linux Enterprise Server 12-SP5 ) libglib-2_0-0-debuginfo-32bit-2.48.2-12.28.1.x86_64.rpmLinux
SUSE-SU-2022:1758-1(SUSE Linux Enterprise Server 12-SP5 ) libgmodule-2_0-0-2.48.2-12.28.1.x86_64.rpmLinux
SUSE-SU-2022:1758-1(SUSE Linux Enterprise Server 12-SP5 ) libgmodule-2_0-0-32bit-2.48.2-12.28.1.x86_64.rpmLinux
SUSE-SU-2022:1758-1(SUSE Linux Enterprise Server 12-SP5 ) libgmodule-2_0-0-debuginfo-2.48.2-12.28.1.x86_64.rpmLinux
SUSE-SU-2022:1758-1(SUSE Linux Enterprise Server 12-SP5 ) libgmodule-2_0-0-debuginfo-32bit-2.48.2-12.28.1.x86_64.rpmLinux
SUSE-SU-2022:1758-1(SUSE Linux Enterprise Server 12-SP5 ) libgobject-2_0-0-2.48.2-12.28.1.x86_64.rpmLinux
SUSE-SU-2022:1758-1(SUSE Linux Enterprise Server 12-SP5 ) libgobject-2_0-0-32bit-2.48.2-12.28.1.x86_64.rpmLinux
SUSE-SU-2022:1758-1(SUSE Linux Enterprise Server 12-SP5 ) libgobject-2_0-0-debuginfo-2.48.2-12.28.1.x86_64.rpmLinux
SUSE-SU-2022:1758-1(SUSE Linux Enterprise Server 12-SP5 ) libgobject-2_0-0-debuginfo-32bit-2.48.2-12.28.1.x86_64.rpmLinux
SUSE-SU-2022:1758-1(SUSE Linux Enterprise Server 12-SP5 ) libgthread-2_0-0-2.48.2-12.28.1.x86_64.rpmLinux
SUSE-SU-2022:1758-1(SUSE Linux Enterprise Server 12-SP5 ) libgthread-2_0-0-32bit-2.48.2-12.28.1.x86_64.rpmLinux
SUSE-SU-2022:1758-1(SUSE Linux Enterprise Server 12-SP5 ) libgthread-2_0-0-debuginfo-2.48.2-12.28.1.x86_64.rpmLinux
SUSE-SU-2022:1758-1(SUSE Linux Enterprise Server 12-SP5 ) libgthread-2_0-0-debuginfo-32bit-2.48.2-12.28.1.x86_64.rpmLinux
SUSE-SU-2023:0794-1(Basesystem Module 15-SP4 ) python3-PyJWT-2.4.0-150200.3.6.2.noarch.rpmLinux
SUSE-SU-2023:0796-1(Basesystem Module 15-SP4 ) kernel-default-5.14.21-150400.24.49.3.x86_64.rpmLinux
SUSE-SU-2023:0796-1(Basesystem Module 15-SP4 ) kernel-default-base-5.14.21-150400.24.49.3.150400.24.19.3.x86_64.rpmLinux
SUSE-SU-2023:0796-1(Basesystem Module 15-SP4 ) kernel-default-debuginfo-5.14.21-150400.24.49.3.x86_64.rpmLinux
SUSE-SU-2023:0796-1(Basesystem Module 15-SP4 ) kernel-default-debugsource-5.14.21-150400.24.49.3.x86_64.rpmLinux
SUSE-SU-2023:0796-1(Basesystem Module 15-SP4 ) kernel-default-devel-5.14.21-150400.24.49.3.x86_64.rpmLinux
SUSE-SU-2023:0796-1(Basesystem Module 15-SP4 ) kernel-default-devel-debuginfo-5.14.21-150400.24.49.3.x86_64.rpmLinux
SUSE-SU-2023:0796-1(Development Tools Module 15-SP4 ) kernel-obs-build-5.14.21-150400.24.49.3.x86_64.rpmLinux
SUSE-SU-2023:0796-1(Development Tools Module 15-SP4 ) kernel-obs-build-debugsource-5.14.21-150400.24.49.3.x86_64.rpmLinux
SUSE-SU-2023:0796-1(Development Tools Module 15-SP4 ) kernel-syms-5.14.21-150400.24.49.4.x86_64.rpmLinux
SUSE-SU-2023:0796-1(Legacy Module 15-SP4 ) reiserfs-kmp-default-5.14.21-150400.24.49.3.x86_64.rpmLinux
SUSE-SU-2023:0796-1(Legacy Module 15-SP4 ) reiserfs-kmp-default-debuginfo-5.14.21-150400.24.49.3.x86_64.rpmLinux
SUSE-SU-2023:0796-1(Basesystem Module 15-SP4 ) kernel-devel-5.14.21-150400.24.49.4.noarch.rpmLinux
SUSE-SU-2023:0796-1(Development Tools Module 15-SP4 ) kernel-docs-5.14.21-150400.24.49.4.noarch.rpmLinux
SUSE-SU-2023:0796-1(Basesystem Module 15-SP4 ) kernel-macros-5.14.21-150400.24.49.4.noarch.rpmLinux
SUSE-SU-2023:0796-1(Development Tools Module 15-SP4 ) kernel-source-5.14.21-150400.24.49.4.noarch.rpmLinux
SUSE-SU-2023:4614-1(SUSE Linux Enterprise Server 12 SP5 ) java-1_8_0-ibm-1.8.0_sr8.15-30.117.1.x86_64.rpmLinux
SUSE-SU-2023:4614-1(SUSE Linux Enterprise Server 12 SP5 ) java-1_8_0-ibm-alsa-1.8.0_sr8.15-30.117.1.x86_64.rpmLinux
SUSE-SU-2023:4614-1(SUSE Linux Enterprise Server 12 SP5 ) java-1_8_0-ibm-devel-1.8.0_sr8.15-30.117.1.x86_64.rpmLinux
SUSE-SU-2023:4614-1(SUSE Linux Enterprise Server 12 SP5 ) java-1_8_0-ibm-plugin-1.8.0_sr8.15-30.117.1.x86_64.rpmLinux
Glib2 update (ELSA-2021-4385) glib2-2.56.4-156.el8.i686.rpmLinux
Glib2 update (ELSA-2021-4385) glib2-2.56.4-156.el8.x86_64.rpmLinux
Glib2-devel update (ELSA-2021-4385) glib2-devel-2.56.4-156.el8.i686.rpmLinux
Glib2-devel update (ELSA-2021-4385) glib2-devel-2.56.4-156.el8.x86_64.rpmLinux
Glib2-fam update (ELSA-2021-4385) glib2-fam-2.56.4-156.el8.x86_64.rpmLinux
Glib2-tests update (ELSA-2021-4385) glib2-tests-2.56.4-156.el8.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234