CVE-2024-34397

An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.
References
Link Resource
https://gitlab.gnome.org/GNOME/glib/-/issues/3268 Exploit Issue Tracking Vendor Advisory
https://lists.debian.org/debian-lts-announce/2024/05/msg00008.html Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IRSFYAE5X23TNRWX7ZWEJOMISLCDSYNS/ Third Party Advisory Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LCDY3KA7G7D3DRXYTT46K6LFHS2KHWBH/ Third Party Advisory Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LL6HSJDXCXMLEIJBYV6CPOR4K2NTCTXW/ Third Party Advisory Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UNFJHISR4O6VFOHBFWH5I5WWMG37H63A/ Third Party Advisory Mailing List
https://security.netapp.com/advisory/ntap-20240531-0008/ Third Party Advisory
https://www.openwall.com/lists/oss-security/2024/05/07/5 Mailing List
https://gitlab.gnome.org/GNOME/glib/-/issues/3268 Exploit Issue Tracking Vendor Advisory
https://lists.debian.org/debian-lts-announce/2024/05/msg00008.html Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IRSFYAE5X23TNRWX7ZWEJOMISLCDSYNS/ Third Party Advisory Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LCDY3KA7G7D3DRXYTT46K6LFHS2KHWBH/ Third Party Advisory Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LL6HSJDXCXMLEIJBYV6CPOR4K2NTCTXW/ Third Party Advisory Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UNFJHISR4O6VFOHBFWH5I5WWMG37H63A/ Third Party Advisory Mailing List
https://security.netapp.com/advisory/ntap-20240531-0008/ Third Party Advisory
https://www.openwall.com/lists/oss-security/2024/05/07/5 Mailing List
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*
cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:*

History

18 Jun 2025, 14:36

Type Values Removed Values Added
First Time Fedoraproject
Fedoraproject fedora
Debian
Gnome glib
Netapp
Gnome
Debian debian Linux
Netapp ontap Tools
References () https://gitlab.gnome.org/GNOME/glib/-/issues/3268 - () https://gitlab.gnome.org/GNOME/glib/-/issues/3268 - Exploit, Issue Tracking, Vendor Advisory
References () https://lists.debian.org/debian-lts-announce/2024/05/msg00008.html - () https://lists.debian.org/debian-lts-announce/2024/05/msg00008.html - Mailing List, Third Party Advisory
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IRSFYAE5X23TNRWX7ZWEJOMISLCDSYNS/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IRSFYAE5X23TNRWX7ZWEJOMISLCDSYNS/ - Third Party Advisory, Mailing List
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LCDY3KA7G7D3DRXYTT46K6LFHS2KHWBH/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LCDY3KA7G7D3DRXYTT46K6LFHS2KHWBH/ - Third Party Advisory, Mailing List
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LL6HSJDXCXMLEIJBYV6CPOR4K2NTCTXW/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LL6HSJDXCXMLEIJBYV6CPOR4K2NTCTXW/ - Third Party Advisory, Mailing List
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UNFJHISR4O6VFOHBFWH5I5WWMG37H63A/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UNFJHISR4O6VFOHBFWH5I5WWMG37H63A/ - Third Party Advisory, Mailing List
References () https://security.netapp.com/advisory/ntap-20240531-0008/ - () https://security.netapp.com/advisory/ntap-20240531-0008/ - Third Party Advisory
References () https://www.openwall.com/lists/oss-security/2024/05/07/5 - () https://www.openwall.com/lists/oss-security/2024/05/07/5 - Mailing List
CPE cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*

Information

Published : 2024-05-07 18:15

Updated : 2025-06-18 14:36


NVD link : CVE-2024-34397

Mitre link : CVE-2024-34397

CVE.ORG link : CVE-2024-34397


JSON object : View

Products Affected

netapp

  • ontap_tools

debian

  • debian_linux

fedoraproject

  • fedora

gnome

  • glib
CWE
CWE-290

Authentication Bypass by Spoofing