CVE-2021-28153: Medium severity ibm security qradar vulnerability
An issue was discovered in GNOME GLib before 2.66.8. When gfilereplace() is used with GFILECREATEREPLACEDESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is attacker-controlled. (If the path is a symlink to a file that already exists, then the contents of that file correctly remain unchanged.)
Other sources
GNOME GLib could allow a remote attacker to bypass security restrictions, caused by a flaw when gfilereplace() function is used with GFILECREATEREPLACEDESTINATION to replace a path that is a dangling symlink. By persuading a victim to open a specially-crafted ZIP archive, an attacker could exploit this vulnerability to overwrite arbitrary files on the sytem.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-28153?
CVE-2021-28153 is a vulnerability in GNOME GLib that could allow a remote attacker to bypass security restrictions.
How does CVE-2021-28153 affect IBM QRadar SIEM?
CVE-2021-28153 affects IBM QRadar SIEM versions 7.5.0 GA, 7.4.3 GA - 7.4.3 FP4, and 7.3.3 GA - 7.3.3 FP10.
What is the severity of CVE-2021-28153?
The severity of CVE-2021-28153 is medium, with a severity value of 5.5.
How can I fix CVE-2021-28153 in IBM QRadar SIEM?
To fix CVE-2021-28153 in IBM QRadar SIEM, you can apply the relevant patches provided by IBM.
Where can I find more information about CVE-2021-28153?
You can find more information about CVE-2021-28153 on the IBM X-Force Exchange and IBM Support pages.