Mageia 2023-0176: glib2.0 security update
Summary
Denial of service caused by handling a malicious text-form variant.
(CVE-2023-24593)
Denial of service caused by malicious serialised variant. (CVE-2023-25180)
References
- https://bugs.mageia.org/show_bug.cgi?id=31805
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/FRPEEZJKIVRRCTBOO42O6IY44O5UU3MT/
- https://lists.suse.com/pipermail/sle-security-updates/2023-April/014499.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24593
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25180
Resolution
MGASA-2023-0176 - Updated glib2.0 packages fix security vulnerability
SRPMS
- 8/core/glib2.0-2.66.8-1.1.mga8