CVE-2024-34397: Medium severity Gnome GLib vulnerability
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.
Other sources
GNOME GLib could allow a remote attacker to conduct spoofing attacks, caused by a flaw when a GDBus-based client subscribes to signals from a trusted system service. By sending specially crafted D-Bus signals, an attacker could exploit this vulnerability perform unicast spoofing attacks.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.64.6-1~ubuntu20.04.7 - Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.72.4-0ubuntu2.3 - Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.78.0-2ubuntu0.1 - Upgrade
Upgrade
ubuntu/glib2.0to a version that resolves this vulnerability.Fixed in 2.80.0-6ubuntu3.1 - Upgrade
Upgrade
debian/glib2.0to a version that resolves this vulnerability.Fixed in 2.66.8-1+deb11u4Fixed in 2.66.8-1+deb11u3Fixed in 2.74.6-2+deb12u3Fixed in 2.74.6-2+deb12u2Fixed in 2.81.1-3 - Upgrade
Upgrade
redhat/glibto a version that resolves this vulnerability.Fixed in 2.78.5 - Upgrade
Upgrade
redhat/glibto a version that resolves this vulnerability.Fixed in 2.80.1 - Upgrade
Upgrade
redhat/glibto a version that resolves this vulnerability.Fixed in 2.81.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34397?
CVE-2024-34397 is considered a medium severity vulnerability due to the potential for spoofed D-Bus signals affecting system services.
How do I fix CVE-2024-34397?
To fix CVE-2024-34397, you should upgrade GNOME GLib to version 2.78.5 or later.
Who is affected by CVE-2024-34397?
CVE-2024-34397 affects users of GNOME GLib versions before 2.78.5 on systems where multiple users share access.
What versions of GNOME GLib are vulnerable to CVE-2024-34397?
GNOME GLib versions prior to 2.78.5, as well as 2.79.x and 2.80.x before 2.80.1, are vulnerable to CVE-2024-34397.
What should I do if I cannot upgrade to the patched version for CVE-2024-34397?
If you cannot upgrade, consider limiting user access or employing additional security measures to mitigate risk associated with CVE-2024-34397.