CVE-2024-52533 gio/gsocks4aproxy.c in GNOME GLib
search cancel

CVE-2024-52533 gio/gsocks4aproxy.c in GNOME GLib

book

Article ID: 385233

calendar_today

Updated On:

Products

VMware Aria Suite VMware vCenter Server

Issue/Introduction

gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.

Environment

VMware Aria Suite Lifecycle 8.x
VMware vCenter Server 8.x

Cause

Gnome glib for GTK support is used in Linux desktop environments and not applicable to VMware products.

Resolution

  • Broadcom has determined the glib shipped with Broadcom applications running photon is not the same as GNOME glib.
  • CVE-2024-52533 was investigated when the CVE was published and observed no impact to Broadcom products. 
  • Since there was no code change, it was not added to the product release notes:
    • The following command returns null: 

      rpm -qa --changelog | grep -A 2 "CVE-#"

Additional Information

https://nvd.nist.gov/vuln/detail/CVE-2024-52533