A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivileged ones under the right condition.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1938284 | patch third party advisory issue tracking |
https://access.redhat.com/security/cve/CVE-2021-3800 | third party advisory |
https://www.openwall.com/lists/oss-security/2017/06/23/8 | patch mailing list exploit third party advisory |
https://gitlab.gnome.org/GNOME/glib/-/commit/3529bb4450a51995 | patch vendor advisory |
https://lists.debian.org/debian-lts-announce/2022/09/msg00020.html | third party advisory mailing list |
https://security.netapp.com/advisory/ntap-20221028-0004/ | third party advisory |