Symlink Attack Affecting glib package, versions [,2.66.8)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.29% (69th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-GLIB-2382566
  • published26 Jan 2022
  • disclosed11 Mar 2021
  • creditUnknown

Introduced: 11 Mar 2021

CVE-2021-28153  (opens in a new tab)
CWE-59  (opens in a new tab)

How to fix?

Upgrade glib to version 2.66.8 or higher.

Overview

Affected versions of this package are vulnerable to Symlink Attack. An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is attacker-controlled. (If the path is a symlink to a file that already exists, then the contents of that file correctly remain unchanged.)

References

CVSS Scores

version 3.1