MEDIUM 5.5 Microsoft
CVE-2021-3800
A flaw was found in glib before version 2.63.6. Due to random charset alias pkexec can leak content from files owned by privileged users to unprivileged ones under the right condition.
Microsoft Security Update 2022-Aug: A flaw was found in glib before version 2.63.6. Due to random charset alias pkexec can leak content from files owned by privileged users to unprivileged ones under the right condition.
Affected Products
- cm1 glib 2.58.0-10 on CBL Mariner 1.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-3800
- https://nvd.nist.gov/vuln/detail/CVE-2021-3800
This medium severity vulnerability with a CVSS score of 5.5 was published on 2022-08-09 via Microsoft. Affected: cm1 glib 2.58.0-10 on CBL Mariner 1.0.
vulnfeed aggregates 9119 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.