CVE-2021-3800

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
23/08/2022
Last modified:
25/04/2023

Description

A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivileged ones under the right condition.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:* 2.62.5 (excluding)
cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:* 2.63.0 (including) 2.63.6 (excluding)
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*