Integer Overflow and Buffer Under-read in GLib Affects Multiple Software Products
CVE-2025-3360
3.7LOW
Summary
A security flaw exists within GLib related to an integer overflow and buffer under-read that occurs when the g_date_time_new_from_iso8601() function attempts to parse an excessively long, invalid ISO 8601 timestamp. This vulnerability could be exploited by attackers to manipulate memory contents, potentially leading to undefined behavior in affected applications.
References
CVSS V3.1
Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved