PT-2019-6657 · Gtk · Ktsuss

Published

2019-11-19

·

Updated

2019-11-21

·

CVE-2011-2922

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ktsuss versions 1.4 and prior
Description The issue allows a local attacker to escalate privileges to root. This can be achieved by spawning the GTK interface to run as root, potentially using the GTK MODULES environment variable to execute arbitrary code.
Recommendations For versions 1.4 and prior, consider disabling the GTK interface or restricting its use to prevent privilege escalation until a fix is available. Avoid using the GTK MODULES environment variable in sensitive environments to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-2922

Affected Products

Ktsuss