Vulnerabilities > CVE-2021-3800
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivileged ones under the right condition.
Vulnerable Configurations
References
- https://access.redhat.com/security/cve/CVE-2021-3800
- https://access.redhat.com/security/cve/CVE-2021-3800
- https://bugzilla.redhat.com/show_bug.cgi?id=1938284
- https://bugzilla.redhat.com/show_bug.cgi?id=1938284
- https://gitlab.gnome.org/GNOME/glib/-/commit/3529bb4450a51995
- https://gitlab.gnome.org/GNOME/glib/-/commit/3529bb4450a51995
- https://lists.debian.org/debian-lts-announce/2022/09/msg00020.html
- https://lists.debian.org/debian-lts-announce/2022/09/msg00020.html
- https://security.netapp.com/advisory/ntap-20221028-0004/
- https://security.netapp.com/advisory/ntap-20221028-0004/
- https://www.openwall.com/lists/oss-security/2017/06/23/8
- https://www.openwall.com/lists/oss-security/2017/06/23/8