Unrated severityNVD Advisory· Published Aug 23, 2022· Updated Aug 3, 2024
CVE-2021-3800
CVE-2021-3800
Description
A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivileged ones under the right condition.
Affected products
7- glib/glibdescription
- osv-coords6 versionspkg:rpm/almalinux/glib2-docpkg:rpm/almalinux/glib2-staticpkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP5
< 2.56.4-156.el8+ 5 more
- (no CPE)range: < 2.56.4-156.el8
- (no CPE)range: < 2.56.4-156.el8
- (no CPE)range: < 2.48.2-12.25.1
- (no CPE)range: < 2.48.2-12.25.1
- (no CPE)range: < 2.48.2-12.25.1
- (no CPE)range: < 2.48.2-12.25.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- lists.debian.org/debian-lts-announce/2022/09/msg00020.htmlmitremailing-list
- access.redhat.com/security/cve/CVE-2021-3800mitre
- bugzilla.redhat.com/show_bug.cgimitre
- gitlab.gnome.org/GNOME/glib/-/commit/3529bb4450a51995mitre
- security.netapp.com/advisory/ntap-20221028-0004/mitre
- www.openwall.com/lists/oss-security/2017/06/23/8mitre
News mentions
0No linked articles in our index yet.