Lucene search

K
jvnJapan Vulnerability NotesJVN:58019849
HistorySep 02, 2011 - 12:00 a.m.

JVN#58019849: GTK+ may insecurely load dynamic libraries

2011-09-0200:00:00
Japan Vulnerability Notes
jvn.jp
14

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

EPSS

0

Percentile

5.1%

GTK+ is a toolkit for developing applications with GUIs. GTK+ contains an issue with the DLL search path, which may lead to insecurely loading dynamic libraries.

Impact

In an application that uses GTK+, arbitrary code may be executed with the privilege of that application.

Solution

Solution for developers using GTK+
Developers that use GTK+ should update GTK+ to the latest version available.

Products Affected

  • GTK+ versions prior to 2.21.8

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

EPSS

0

Percentile

5.1%