PT-2012-1088 · Red Hat+2 · Spice-Gtk+9

Sebastian Krahmer

·

Published

2012-09-17

·

Updated

2024-06-15

·

CVE-2012-4425

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions spice-gtk versions 0.11 spice-gtk-tools versions 0.11 spice-gtk-python versions 0.11 spice-glib versions 0.11 spice-gtk-devel versions 0.11 spice-glib-devel versions 0.11 spice-gtk-debuginfo versions 0.11
Description The issue allows local users to gain privileges and execute arbitrary code via the DBUS SYSTEM BUS ADDRESS environment variable. This could lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be carried out locally.
Recommendations For spice-gtk version 0.11, consider disabling the use of the DBUS SYSTEM BUS ADDRESS environment variable until a patch is available. For spice-gtk-tools version 0.11, restrict access to sensitive information to minimize the risk of exploitation. For spice-gtk-python version 0.11, avoid using privileged programs that do not cleanse environment variables. For spice-glib version 0.11, consider implementing additional security measures to prevent local exploitation. For spice-gtk-devel version 0.11, restrict access to development tools to prevent unauthorized use. For spice-glib-devel version 0.11, consider disabling the use of sensitive functions until a patch is available. For spice-gtk-debuginfo version 0.11, restrict access to debug information to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06915
BDU:2015-06917
BDU:2015-06919
BDU:2015-06921
BDU:2015-06923
BDU:2015-06925
BDU:2015-06927
BDU:2015-08877
BDU:2015-08878
BDU:2015-08879
BDU:2015-08880
BDU:2015-08881
CESA-2012_1284
CVE-2012-4425
OPENSUSE-SU-2024:10421-1
RHSA-2012:1284
RHSA-2012_1284

Affected Products

Centos
Dbus
Red Hat
Spice-Glib
Spice-Glib-Devel
Spice-Gtk
Spice-Gtk-Debuginfo
Spice-Gtk-Devel
Spice-Gtk-Python
Spice-Gtk-Tools