CVE-2021-3800
23.08.2022, 16:15
A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivileged ones under the right condition.Enginsight
| Vendor | Product | Version |
|---|---|---|
| gnome | glib | 𝑥 < 2.62.5 |
| gnome | glib | 2.63.0 ≤ 𝑥 < 2.63.6 |
| debian | debian_linux | 10.0 |
| netapp | active_iq_unified_manager | - |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- CWE-552 - Files or Directories Accessible to External PartiesThe product makes files or directories accessible to unauthorized actors, even though they should not be.
References