Vulnerability in GLib Affects Privileged File Access on Linux Systems
CVE-2021-3800

5.5MEDIUM

Key Information:

Vendor
Gnome
Status
Vendor
CVE Published:
23 August 2022

Summary

A security flaw in GLib prior to version 2.63.6 allows pkexec to inadvertently leak content from files owned by privileged users to unprivileged users under specific conditions. This can lead to potential unauthorized access to sensitive information, highlighting a significant concern for system security and data integrity in Linux environments.

Affected Version(s)

Glib Fixed in glib2 2.63.6

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.