yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2024-52533
Component Overview
Vulnerability Overview
Name
CVE-2024-52533
Source
NVD (
link
)
Debian (
link
)
Description
gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.
CWEs
CWE-120
Published Date
Nov 11, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://gitlab.gnome.org/GNOME/glib/-/issues/3461
Exploit
https://gitlab.gnome.org/GNOME/glib/-/releases/2.82.1
Release Notes
https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home
Vendor Advisory
http://www.openwall.com/lists/oss-security/2024/11/12/11
Mailing List
https://lists.debian.org/debian-lts-announce/2024/11/msg00020.html
Mailing List
https://security.netapp.com/advisory/ntap-20241206-0009/
Third Party Advisory
Analysis
#
Affected Component
Analysis
glib-2.0
Patched
Vulnerability Ratings
#
9.8
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
glib-2.0
yocto
master
2.88.1
Not Affected
glib-2.0
yocto
scarthgap
2.78.6
Patched
Resolved with patches
#
glib-2.0 (yocto:kirkstone)
#
Title
Author
Resolve
1
gsocks4aproxy: Fix a single byte buffer overflow in connect
Michael Catanzaro <mcatanzaro@redhat.com>
CVE-2024-52533
glib-2.0 (yocto:scarthgap)
#
Title
Author
Resolve
1
gsocks4aproxy: Fix a single byte buffer overflow in connect
Michael Catanzaro <mcatanzaro@redhat.com>
CVE-2024-52533