libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: it could be argued that this is a vulnerability in the applications that do not cleanse environment variables, not in libgio itself.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade spice-gtk-pythonUpgrade spice-gtk-toolsUpgrade spice-gtk-develUpgrade spice-glibUpgrade spice-glib-develUpgrade spice-gtk | Dec 1, 2016 | Sep 18, 2012 |
| Debian | — | Upgrade spice-gtk | Jul 30, 2024 | Sep 18, 2012 |
| Gentoo Linux | — | Upgrade net-misc/spice-gtk. | Oct 30, 2017 | Sep 18, 2012 |
| Oracle_linux | — | Upgrade spice-gtk-pythonUpgrade spice-glibUpgrade spice-gtk-develUpgrade spice-gtkUpgrade spice-glib-develUpgrade spice-gtk-tools | Oct 16, 2024 | Sep 18, 2012 |
| Suse | — | Upgrade libspice-client-gtk-2_0-4Upgrade libspice-client-glib-helperUpgrade typelib-1_0-SpiceClientGlib-2_0Upgrade typelib-1_0-SpiceClientGtk-3_0Upgrade libspice-client-gtk-3_0-4Upgrade libspice-client-glib-2_0-8Upgrade libspice-client-gtk-3_0-5Upgrade libspice-controller0Upgrade typelib-1_0-SpiceClientGtk-2_0Upgrade spice-gtk-devel | Aug 9, 2024 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub