Bug#1107797: glib2.0: CVE-2025-6052

2025-06-15 Thread Simon McVittie
On Sun, 15 Jun 2025 at 08:16:20 +0200, Salvatore Bonaccorso wrote: On Sat, Jun 14, 2025 at 11:15:00PM +0100, Simon McVittie wrote: On Sat, 14 Jun 2025 at 22:51:55 +0200, Salvatore Bonaccorso wrote: > [1] https://gitlab.gnome.org/GNOME/glib/-/merge_requests/4655 I don't think this is plausibly a

Bug#1107797: glib2.0: CVE-2025-6052

2025-06-14 Thread Salvatore Bonaccorso
Hi Simon, On Sat, Jun 14, 2025 at 11:15:00PM +0100, Simon McVittie wrote: > On Sat, 14 Jun 2025 at 22:51:55 +0200, Salvatore Bonaccorso wrote: > > [1] https://gitlab.gnome.org/GNOME/glib/-/merge_requests/4655 > > I don't think this is plausibly attacker-triggerable: it would require an > attacker

Bug#1107797: glib2.0: CVE-2025-6052

2025-06-14 Thread Simon McVittie
On Sat, 14 Jun 2025 at 22:51:55 +0200, Salvatore Bonaccorso wrote: [1] https://gitlab.gnome.org/GNOME/glib/-/merge_requests/4655 I don't think this is plausibly attacker-triggerable: it would require an attacker to be able to cause succesful (!) allocation of a GString object, and some data t

Bug#1107797: glib2.0: CVE-2025-6052

2025-06-14 Thread Salvatore Bonaccorso
Source: glib2.0 Version: 2.75.3-1 Severity: important Tags: security upstream Forwarded: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/4655 X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for glib2.0. CVE-2025-6052[0]: | A flaw was foun