Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11167
HistoryJan 15, 2019 - 8:57 a.m.

Arbitrary Code Execution

2019-01-1508:57:53
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

0.0004 Low

EPSS

Percentile

5.1%

spice-gtk is vulnerable to arbitrary code execution attacks. The vulnerability exists as libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: it could be argued that this is a vulnerability in the applications that do not cleanse environment variables, not in libgio itself.

CPENameOperatorVersion
spice-gtkeq0.6__2.el6
spice-gtkeq0.6__2.el6