gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.
References
Link | Resource |
---|---|
https://gitlab.gnome.org/GNOME/glib/-/issues/3461 | Exploit Issue Tracking |
https://gitlab.gnome.org/GNOME/glib/-/releases/2.82.1 | Release Notes |
https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home | Vendor Advisory |
http://www.openwall.com/lists/oss-security/2024/11/12/11 | Mailing List |
https://lists.debian.org/debian-lts-announce/2024/11/msg00020.html | Mailing List Third Party Advisory |
https://security.netapp.com/advisory/ntap-20241206-0009/ | Third Party Advisory |
Configurations
History
17 Jun 2025, 01:23
Type | Values Removed | Values Added |
---|---|---|
First Time |
Netapp
Debian Debian debian Linux Netapp active Iq Unified Manager Gnome Netapp ontap Tools Gnome glib |
|
References | () https://gitlab.gnome.org/GNOME/glib/-/issues/3461 - Exploit, Issue Tracking | |
References | () https://gitlab.gnome.org/GNOME/glib/-/releases/2.82.1 - Release Notes | |
References | () https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home - Vendor Advisory | |
References | () http://www.openwall.com/lists/oss-security/2024/11/12/11 - Mailing List | |
References | () https://lists.debian.org/debian-lts-announce/2024/11/msg00020.html - Mailing List, Third Party Advisory | |
References | () https://security.netapp.com/advisory/ntap-20241206-0009/ - Third Party Advisory | |
CPE | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:* cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:* |
06 Dec 2024, 14:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
23 Nov 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
21 Nov 2024, 09:46
Type | Values Removed | Values Added |
---|---|---|
References |
|
12 Nov 2024, 16:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-120 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
12 Nov 2024, 13:55
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
11 Nov 2024, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-11 23:15
Updated : 2025-06-17 01:23
NVD link : CVE-2024-52533
Mitre link : CVE-2024-52533
CVE.ORG link : CVE-2024-52533
JSON object : View
Products Affected
netapp
- active_iq_unified_manager
- ontap_tools
debian
- debian_linux
gnome
- glib
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')