An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Glib | Gnome | * | 2.78.5 (excluding) |
Glib | Gnome | 2.79.0 (including) | 2.80.1 (excluding) |
Red Hat Enterprise Linux 8 | RedHat | glib2-0:2.56.4-166.el8_10 | * |
Red Hat Enterprise Linux 9 | RedHat | rhel9/toolbox:9.4-12.1725906880 | * |
Red Hat Enterprise Linux 9 | RedHat | ubi9/toolbox:9.4-12.1725906880 | * |
Red Hat Enterprise Linux 9 | RedHat | glib2-0:2.68.4-14.el9_4.1 | * |
Red Hat Enterprise Linux 9 | RedHat | mingw-glib2-0:2.78.6-1.el9 | * |
Red Hat Enterprise Linux 9 | RedHat | glib2-0:2.68.4-14.el9_4.1 | * |
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | RedHat | glib2-0:2.68.4-7.el9_2 | * |
Service Interconnect 1.4 for RHEL 9 | RedHat | service-interconnect/skupper-config-sync-rhel9:1.4.7-3 | * |
Service Interconnect 1.4 for RHEL 9 | RedHat | service-interconnect/skupper-flow-collector-rhel9:1.4.7-3 | * |
Service Interconnect 1.4 for RHEL 9 | RedHat | service-interconnect/skupper-operator-bundle:1.4.7-4 | * |
Service Interconnect 1.4 for RHEL 9 | RedHat | service-interconnect/skupper-router-rhel9:2.4.3-7 | * |
Service Interconnect 1.4 for RHEL 9 | RedHat | service-interconnect/skupper-service-controller-rhel9:1.4.7-3 | * |
Service Interconnect 1.4 for RHEL 9 | RedHat | service-interconnect/skupper-site-controller-rhel9:1.4.7-3 | * |
Service Interconnect 1.4 for RHEL 9 | RedHat | service-interconnect/skupper-config-sync-rhel9:1.4.7-2 | * |
Service Interconnect 1.4 for RHEL 9 | RedHat | service-interconnect/skupper-flow-collector-rhel9:1.4.7-2 | * |
Service Interconnect 1.4 for RHEL 9 | RedHat | service-interconnect/skupper-operator-bundle:1.4.7-2 | * |
Service Interconnect 1.4 for RHEL 9 | RedHat | service-interconnect/skupper-router-rhel9:2.4.3-6 | * |
Service Interconnect 1.4 for RHEL 9 | RedHat | service-interconnect/skupper-service-controller-rhel9:1.4.7-2 | * |
Service Interconnect 1.4 for RHEL 9 | RedHat | service-interconnect/skupper-site-controller-rhel9:1.4.7-2 | * |
Service Interconnect 1 for RHEL 9 | RedHat | service-interconnect/skupper-config-sync-rhel9:1.5.5-4 | * |
Service Interconnect 1 for RHEL 9 | RedHat | service-interconnect/skupper-controller-podman-container-rhel9:1.5.5-4 | * |
Service Interconnect 1 for RHEL 9 | RedHat | service-interconnect/skupper-controller-podman-rhel9:1.5.5-4 | * |
Service Interconnect 1 for RHEL 9 | RedHat | service-interconnect/skupper-flow-collector-rhel9:1.5.5-4 | * |
Service Interconnect 1 for RHEL 9 | RedHat | service-interconnect/skupper-operator-bundle:1.5.5-4 | * |
Service Interconnect 1 for RHEL 9 | RedHat | service-interconnect/skupper-router-rhel9:2.5.3-6 | * |
Service Interconnect 1 for RHEL 9 | RedHat | service-interconnect/skupper-service-controller-rhel9:1.5.5-4 | * |
Service Interconnect 1 for RHEL 9 | RedHat | service-interconnect/skupper-site-controller-rhel9:1.5.5-4 | * |
Service Interconnect 1 for RHEL 9 | RedHat | service-interconnect/skupper-config-sync-rhel9:1.5.5-3 | * |
Service Interconnect 1 for RHEL 9 | RedHat | service-interconnect/skupper-controller-podman-container-rhel9:1.5.5-3 | * |
Service Interconnect 1 for RHEL 9 | RedHat | service-interconnect/skupper-controller-podman-rhel9:1.5.5-3 | * |
Service Interconnect 1 for RHEL 9 | RedHat | service-interconnect/skupper-flow-collector-rhel9:1.5.5-3 | * |
Service Interconnect 1 for RHEL 9 | RedHat | service-interconnect/skupper-operator-bundle:1.5.5-3 | * |
Service Interconnect 1 for RHEL 9 | RedHat | service-interconnect/skupper-router-rhel9:2.5.3-5 | * |
Service Interconnect 1 for RHEL 9 | RedHat | service-interconnect/skupper-service-controller-rhel9:1.5.5-3 | * |
Service Interconnect 1 for RHEL 9 | RedHat | service-interconnect/skupper-site-controller-rhel9:1.5.5-3 | * |
Red Hat OpenShift distributed tracing 3.6.1 | RedHat | registry.redhat.io/rhosdt/jaeger-agent-rhel8:sha256:389b9cbd0f05d3d773edc2c06aa73818307cbb25048bddf4f192a992670b6fb4 | * |
Red Hat OpenShift distributed tracing 3.6.1 | RedHat | registry.redhat.io/rhosdt/jaeger-all-in-one-rhel8:sha256:d9ca4a9ec5bc8de23e4550387f822f19949cdfbc4aeeab20e07b206d92f4a426 | * |
Red Hat OpenShift distributed tracing 3.6.1 | RedHat | registry.redhat.io/rhosdt/jaeger-collector-rhel8:sha256:3dc773cc4a48041bfe69b516db58d2a5060059725351fc1dbcece64778a35b3a | * |
Red Hat OpenShift distributed tracing 3.6.1 | RedHat | registry.redhat.io/rhosdt/jaeger-es-index-cleaner-rhel8:sha256:d0ee4c371754848f57e6b7c5fcf716a7d830cd72b65b8aeb30e78a8e26b40548 | * |
Red Hat OpenShift distributed tracing 3.6.1 | RedHat | registry.redhat.io/rhosdt/jaeger-es-rollover-rhel8:sha256:fe1c8fe5bdc4114a4718812d718fc6b913465e23fd39cf6aa05acb352bd80874 | * |
Red Hat OpenShift distributed tracing 3.6.1 | RedHat | registry.redhat.io/rhosdt/jaeger-ingester-rhel8:sha256:2e6d535aa3208ca8ae1bc588393c8bc499c4bfb452aceca047523502ddffa0ed | * |
Red Hat OpenShift distributed tracing 3.6.1 | RedHat | registry.redhat.io/rhosdt/jaeger-operator-bundle:sha256:be3feca3b19ac609e5ef829887b6d03ca3c504163ed0f9e10b2410cdfb175b72 | * |
Red Hat OpenShift distributed tracing 3.6.1 | RedHat | registry.redhat.io/rhosdt/jaeger-query-rhel8:sha256:03f040cf94f7d8125f2e68bde45faa956dc9e70fef6307313e42af5de9bbfda0 | * |
Red Hat OpenShift distributed tracing 3.6.1 | RedHat | registry.redhat.io/rhosdt/jaeger-rhel8-operator:sha256:8fb68adefecd8ccb94404399ac6c8038c064c85287f4f980a0855da1cbd0dcb7 | * |
Glib2.0 | Ubuntu | devel | * |
Glib2.0 | Ubuntu | focal | * |
Glib2.0 | Ubuntu | jammy | * |
Glib2.0 | Ubuntu | mantic | * |
Glib2.0 | Ubuntu | noble | * |
Glib2.0 | Ubuntu | oracular | * |
Glib2.0 | Ubuntu | plucky | * |
Glib2.0 | Ubuntu | trusty/esm | * |