CVE-2021-28153 - log back

CVE-2021-28153 edited at 18 Mar 2021 16:18:17
References
https://gitlab.gnome.org/GNOME/glib/-/issues/2325
https://gitlab.gnome.org/GNOME/glib/-/merge_requests/1981
- https://gitlab.gnome.org/GNOME/glib/-/commit/317b3b587058a05dca95d56dac26568c5b098d33
+ https://gitlab.gnome.org/GNOME/glib/-/commit/87e19535fe2a33b880883128370fe49aa9f906b1
CVE-2021-28153 edited at 12 Mar 2021 00:10:33
Severity
- Unknown
+ Low
Remote
- Unknown
+ Local
Type
- Unknown
+ Arbitrary file upload
Description
+ An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is attacker-controlled. (If the path is a symlink to a file that already exists, then the contents of that file correctly remain unchanged.)
References
+ https://gitlab.gnome.org/GNOME/glib/-/issues/2325
+ https://gitlab.gnome.org/GNOME/glib/-/merge_requests/1981
+ https://gitlab.gnome.org/GNOME/glib/-/commit/317b3b587058a05dca95d56dac26568c5b098d33
Notes
CVE-2021-28153 created at 11 Mar 2021 23:47:45