CVE-2023-32611
G_variant_byteswap() can take a long time with some non-normal inputs
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading to denial of service.
Se encontró una falla en GLib. La deserialización de GVariant es vulnerable a un problema de desaceleración en el que un GVariant manipulado puede provocar un procesamiento excesivo y provocar una denegación de servicio.
USN-6165-1 fixed vulnerabilities in GLib. This update provides the corresponding updates for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. It was discovered that GLib incorrectly handled non-normal GVariants. An attacker could use this issue to cause GLib to crash, resulting in a denial of service, or perform other unknown attacks.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-05-30 CVE Reserved
- 2023-09-14 CVE Published
- 2024-12-19 EPSS Updated
- 2025-02-13 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
- CWE-502: Deserialization of Untrusted Data
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2023/09/msg00030.html |
|
|
https://security.gentoo.org/glsa/202311-18 |
|
|
https://security.netapp.com/advisory/ntap-20231027-0005 |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2023-32611 | 2023-11-27 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2211829 | 2023-11-27 | |
https://gitlab.gnome.org/GNOME/glib/-/issues/2797 | 2023-11-27 |