The vendor explicitly identifies these products as affected by this CVE.
- glib2 as a component of Red Hat Enterprise Linux 6
- glib2-devel as a component of Red Hat Enterprise Linux 6
- glib2-doc as a component of Red Hat Enterprise Linux 6
- glib2-static as a component of Red Hat Enterprise Linux 6
- glib2.src as a component of Red Hat Enterprise Linux 6
- glib2 as a component of Red Hat Enterprise Linux 7
- glib2-devel as a component of Red Hat Enterprise Linux 7
- glib2-doc as a component of Red Hat Enterprise Linux 7
- glib2-fam as a component of Red Hat Enterprise Linux 7
- glib2-static as a component of Red Hat Enterprise Linux 7
- glib2-tests as a component of Red Hat Enterprise Linux 7
- glib2.src as a component of Red Hat Enterprise Linux 7
- Summary
- A flaw was found in GNOME GLib. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This issue could lead to the GDBus-based client behaving incorrectly with an application-dependent impact.
- Remediation
- Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
