PT-2012-1088 · Red Hat+2 · Spice-Gtk+9

Sebastian Krahmer

·

Publicado

2012-09-17

·

Atualizado

2024-06-15

·

CVE-2012-4425

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions spice-gtk versions 0.11 spice-gtk-tools versions 0.11 spice-gtk-python versions 0.11 spice-glib versions 0.11 spice-gtk-devel versions 0.11 spice-glib-devel versions 0.11 spice-gtk-debuginfo versions 0.11
Description The issue allows local users to gain privileges and execute arbitrary code via the DBUS SYSTEM BUS ADDRESS environment variable. This could lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be carried out locally.
Recommendations For spice-gtk version 0.11, consider disabling the use of the DBUS SYSTEM BUS ADDRESS environment variable until a patch is available. For spice-gtk-tools version 0.11, restrict access to sensitive information to minimize the risk of exploitation. For spice-gtk-python version 0.11, avoid using privileged programs that do not cleanse environment variables. For spice-glib version 0.11, consider implementing additional security measures to prevent local exploitation. For spice-gtk-devel version 0.11, restrict access to development tools to prevent unauthorized use. For spice-glib-devel version 0.11, consider disabling the use of sensitive functions until a patch is available. For spice-gtk-debuginfo version 0.11, restrict access to debug information to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06915
BDU:2015-06917
BDU:2015-06919
BDU:2015-06921
BDU:2015-06923
BDU:2015-06925
BDU:2015-06927
BDU:2015-08877
BDU:2015-08878
BDU:2015-08879
BDU:2015-08880
BDU:2015-08881
CESA-2012_1284
CVE-2012-4425
OPENSUSE-SU-2024:10421-1
RHSA-2012:1284
RHSA-2012_1284

Produtos afetados

Centos
Dbus
Red Hat
Spice-Glib
Spice-Glib-Devel
Spice-Gtk
Spice-Gtk-Debuginfo
Spice-Gtk-Devel
Spice-Gtk-Python
Spice-Gtk-Tools