CVE-2023-29499
Public on 2023-06-06
Modified on 2024-01-30
Description
GLib's GVariant deserialization prior to GLib 2.74.4 failed to validate the input conforms to the expected format, leading to denial of service.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
HAQM Linux 1 | glib2 | Pending Fix | ||
HAQM Linux 2 - Core | glib2 | 2025-02-12 | ALAS2-2025-2767 | Fixed |
HAQM Linux 2023 | glib2 | 2023-06-21 | ALAS2023-2023-225 | Fixed |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
HAQM Linux | CVSSv3 | 5.5 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
NVD | CVSSv3 | 7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |