CVE-2008-4316

Publication date 14 March 2009

Last updated 24 July 2024


Ubuntu priority

Multiple integer overflows in glib/gbase64.c in GLib before 2.20 allow context-dependent attackers to execute arbitrary code via a long string that is converted either (1) from or (2) to a base64 representation.

Read the notes from the security team

Status

Package Ubuntu Release Status
glib2.0 8.10 intrepid
Fixed 2.18.2-0ubuntu2.1
8.04 LTS hardy
Fixed 2.16.6-0ubuntu1.1
7.10 gutsy
Fixed 2.14.1-1ubuntu1.1
6.06 LTS dapper
Not affected

Notes


jdstrand

vulnerable code does not exist in Ubuntu 6.06 (code not added until 2.12)

References

Related Ubuntu Security Notices (USN)

Other references