PT-2019-6657 · Gtk · Ktsuss

Publicado

2019-11-19

·

Atualizado

2019-11-21

·

CVE-2011-2922

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ktsuss versions 1.4 and prior
Description The issue allows a local attacker to escalate privileges to root. This can be achieved by spawning the GTK interface to run as root, potentially using the GTK MODULES environment variable to execute arbitrary code.
Recommendations For versions 1.4 and prior, consider disabling the GTK interface or restricting its use to prevent privilege escalation until a fix is available. Avoid using the GTK MODULES environment variable in sensitive environments to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-2922

Produtos afetados

Ktsuss