spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade polkitUpgrade spice-gtk.Upgrade libvirt | Aug 30, 2017 | Oct 3, 2013 |
| Centos_linux | — | Upgrade spice-gtk-toolsUpgrade spice-gtk-develUpgrade spice-gtk-pythonUpgrade spice-glibUpgrade spice-gtkUpgrade spice-glib-devel | Dec 1, 2016 | Oct 3, 2013 |
| Debian | — | Upgrade spice-gtk | Jul 30, 2024 | Oct 3, 2013 |
| Gentoo Linux | — | Upgrade net-misc/spice-gtk.Upgrade sys-auth/polkit.Upgrade net-print/hplip.Upgrade sys-apps/systemd.Upgrade app-emulation/libvirt. | Oct 30, 2017 | Oct 3, 2013 |
| Oracle_linux | — | Upgrade spice-glib-develUpgrade spice-gtk-toolsUpgrade spice-gtk-pythonUpgrade spice-gtk-develUpgrade spice-gtkUpgrade spice-glib | Oct 16, 2024 | Oct 3, 2013 |
| Suse | — | Upgrade libspice-client-gtk-2_0-1Upgrade typelib-1_0-SpiceClientGlib-2_0Upgrade libspice-client-gtk-3_0-1Upgrade spice-gtkUpgrade libspice-client-gtk-3_0-4Upgrade spice-gtk-develUpgrade libspice-controller0Upgrade typelib-1_0-SpiceClientGtk-2_0Upgrade typelib-1_0-SpiceClientGtk-3_0Upgrade libspice-client-gtk-2_0-4Upgrade spice-gtk-langUpgrade libspice-client-glib-2_0-1Upgrade libspice-client-glib-2_0-8Upgrade python-SpiceClientGtk | Dec 12, 2013 | Oct 3, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub