JLSEC-2025-166
Dashboard / Vulnerabilities / JLSEC-2025-166
Summary: `gio/gsocks4aproxy.c` in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer...
Details: `gio/gsocks4aproxy.c` in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because `SOCKS4_CONN_MSG_LEN` is not sufficient for a trailing '\0' character.
References: http://www.openwall.com/lists/oss-security/2024/11/12/11, https://gitlab.gnome.org/GNOME/glib/-/issues/3461, https://gitlab.gnome.org/GNOME/glib/-/releases/2.82.1, https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home, https://lists.debian.org/debian-lts-announce/2024/11/msg00020.html, https://security.netapp.com/advisory/ntap-20241206-0009/
Affected packages
Package
Name: Glib_jll
Purl: pkg:julia/Glib_jll?uuid=7746bdde-850d-59dc-9ae8-88ece973131d
Affected ranges
Type: SEMVER
Events:
