« Volver al listado

CVE-2023-32665

Estado: ModificadaMedia (5.5)—

A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processing, leading to denial of service.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-32665",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-32665",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2023-11-27T17:04:41.563399Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secalert@redhat.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "glib2",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/o:redhat:enterprise_linux:6"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 6",
          "packageName": "glib2",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:/o:redhat:enterprise_linux:7"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 7",
          "packageName": "glib2",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:/o:redhat:enterprise_linux:8"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 8",
          "packageName": "glib2",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/o:redhat:enterprise_linux:9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux 9",
          "packageName": "glib2",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "vendor": "Fedora",
          "product": "Fedora 38",
          "packageName": "glib2",
          "collectionURL": "https://packages.fedoraproject.org/",
          "defaultStatus": "affected"
        },
        {
          "vendor": "Fedora",
          "product": "Extra Packages for Enterprise Linux",
          "packageName": "glib",
          "collectionURL": "https://packages.fedoraproject.org/",
          "defaultStatus": "affected"
        },
        {
          "vendor": "Fedora",
          "product": "Fedora",
          "packageName": "glib2",
          "collectionURL": "https://packages.fedoraproject.org/",
          "defaultStatus": "affected"
        },
        {
          "vendor": "Fedora",
          "product": "Fedora 37",
          "packageName": "glib2",
          "collectionURL": "https://packages.fedoraproject.org/",
          "defaultStatus": "affected"
        },
        {
          "vendor": "Fedora",
          "product": "Fedora 38",
          "packageName": "mingw-glib2",
          "collectionURL": "https://packages.fedoraproject.org/",
          "defaultStatus": "affected"
        },
        {
          "vendor": "Fedora",
          "product": "Fedora 37",
          "packageName": "mingw-glib2",
          "collectionURL": "https://packages.fedoraproject.org/",
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2023-09-14T20:15:09.883",
  "references": [
    {
      "url": "https://access.redhat.com/security/cve/CVE-2023-32665",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2211827",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/2121",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00030.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://security.gentoo.org/glsa/202311-18",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20240426-0006/",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2023-32665",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2211827",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/2121",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00030.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.gentoo.org/glsa/202311-18",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20240426-0006/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-502"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processing, leading to denial of service."
    },
    {
      "lang": "es",
      "value": "Se encontró una falla en GLib. La deserialización de GVariant es vulnerable a un problema de explosión exponencial en el que un GVariant manipulado puede provocar un procesamiento excesivo y provocar una denegación de servicio."
    }
  ],
  "lastModified": "2026-06-17T05:59:20.370",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9DF67CEA-BB12-4E90-9788-1AD9EF0FCB38",
              "versionEndExcluding": "2.74.4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}