{"id":"SUSE-SU-2019:1596-1","summary":"Security update for glib2","details":"This update for glib2 fixes the following issues:\n\nSecurity issues fixed:    \n\n- CVE-2019-12450: Fixed an improper file permission when copy operation\n  takes place (bsc#1137001).     \n- CVE-2018-16428: Avoid a NULL pointer dereference (bsc#1107121).\n- CVE-2018-16429: Fixed out-of-bounds read vulnerability ing_markup_parse_context_parse() (bsc#1107116).\n- Some exploitable parser bugs in GVariant and GDBus subsystems were fixed (bsc#1111499).\n\n","modified":"2026-02-04T03:51:40.485800Z","published":"2019-06-21T08:18:06Z","related":["CVE-2018-16428","CVE-2018-16429","CVE-2019-12450"],"upstream":["CVE-2018-16428","CVE-2018-16429","CVE-2019-12450"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2019/suse-su-20191596-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1107116"},{"type":"REPORT","url":"https://bugzilla.suse.com/1107121"},{"type":"REPORT","url":"https://bugzilla.suse.com/1111499"},{"type":"REPORT","url":"https://bugzilla.suse.com/1137001"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16428"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16429"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-12450"}],"affected":[{"package":{"name":"glib2","ecosystem":"SUSE:Linux Enterprise Server 12-LTSS","purl":"pkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.38.2-7.9.2"}]}],"ecosystem_specific":{"binaries":[{"libglib-2_0-0-32bit":"2.38.2-7.9.2","libglib-2_0-0":"2.38.2-7.9.2","libgmodule-2_0-0-32bit":"2.38.2-7.9.2","libgmodule-2_0-0":"2.38.2-7.9.2","libgobject-2_0-0-32bit":"2.38.2-7.9.2","libgobject-2_0-0":"2.38.2-7.9.2","libgio-2_0-0-32bit":"2.38.2-7.9.2","libgio-2_0-0":"2.38.2-7.9.2","libgthread-2_0-0-32bit":"2.38.2-7.9.2","libgthread-2_0-0":"2.38.2-7.9.2","glib2-lang":"2.38.2-7.9.2","glib2-tools":"2.38.2-7.9.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:1596-1.json"}},{"package":{"name":"glib2","ecosystem":"SUSE:Linux Enterprise Server 12 SP1-LTSS","purl":"pkg:rpm/suse/glib2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.38.2-7.9.2"}]}],"ecosystem_specific":{"binaries":[{"libgio-2_0-0":"2.38.2-7.9.2","libglib-2_0-0-32bit":"2.38.2-7.9.2","libgobject-2_0-0":"2.38.2-7.9.2","glib2-tools":"2.38.2-7.9.2","libglib-2_0-0":"2.38.2-7.9.2","libgmodule-2_0-0-32bit":"2.38.2-7.9.2","libgmodule-2_0-0":"2.38.2-7.9.2","libgobject-2_0-0-32bit":"2.38.2-7.9.2","libgthread-2_0-0-32bit":"2.38.2-7.9.2","libgthread-2_0-0":"2.38.2-7.9.2","glib2-lang":"2.38.2-7.9.2","libgio-2_0-0-32bit":"2.38.2-7.9.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:1596-1.json"}}],"schema_version":"1.7.3"}