CVE-2024-52533: Buffer overflow in socks proxy code in glib < 2.82.1
Published Nov 11, 2024
·Updated
gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4CONNMSGLEN is not sufficient for a trailing '\0' character.
Affected Software
12 affected componentsFixes available
debian/glib2.0<=2.66.8-1+deb11u4, <=2.66.8-1+deb11u3, <=2.74.6-2+deb12u4, <=2.74.6-2+deb12u2
2.82.2-22.82.2-3
Gnome GLib<2.82.1
Debian Debian Linux=11.0
NetApp Active Iq Unified Manager Vmware Vsphere
NetApp Ontap Tools Vmware Vsphere=10
IBM DS8A00( R10.0 - R10.1 )<=10.1.3.0 - 10.10.106.0
IBM DS8900F ( R9.4)<=89.40.83.0-89.44.5.0
Microsoft cbl2 glib 2.71.0-4
Microsoft azl3 glib 2.78.6-1
Microsoft cbl2 glib 2.71.0-4
Microsoft cbl2 glib 2.71.0-3
Microsoft azl3 glib 2.78.1-5
Event History
Nov 11, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via Red Hat·11:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Nov 16, 2024
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
DescriptionSeverity
Updated
via Microsoft·08:00 AM
Description
Nov 18, 2024
Data Sourced
via Ubuntu·07:18 PM
RemedyDescriptionSeverityAffected Software
Dec 18, 2025
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-52533?
CVE-2024-52533 is classified as a high severity vulnerability due to the potential for a buffer overflow.
2
How do I fix CVE-2024-52533?
To fix CVE-2024-52533, upgrade to glib2.0 versions 2.82.2-2 or 2.82.2-3.
3
Which versions of GNOME GLib are affected by CVE-2024-52533?
CVE-2024-52533 affects GNOME GLib versions prior to 2.82.1.
4
What type of vulnerability is CVE-2024-52533?
CVE-2024-52533 is an off-by-one error leading to a buffer overflow.
5
What can happen if CVE-2024-52533 is exploited?
Exploitation of CVE-2024-52533 may allow an attacker to execute arbitrary code in the context of the affected application.