SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-28153

When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is…

MEDIUM 5.3EPSS 2.62%

Does this matter?

Lower severity and a low EPSS score (2.62%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is attacker-controlled. (If the path is a symlink to a file that already exists, then the contents of that file correctly remain unchanged.)

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
2.62% probability · 85th percentile
CISA KEV
Not listed
Weakness
CWE-59
Affected
gnome/glib · broadcom/brocade fabric operating system firmware · debian/debian linux · fedoraproject/fedora
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.