LWN.net Logo

spice-gtk: privilege escalation

Package(s):spice-gtk CVE #(s):CVE-2012-4425
Created:September 18, 2012 Updated:October 4, 2012
Description: From the Red Hat advisory:

It was discovered that the spice-gtk setuid helper application, spice-client-glib-usb-acl-helper, did not clear the environment variables read by the libraries it uses. A local attacker could possibly use this flaw to escalate their privileges by setting specific environment variables before running the helper application.

Alerts:
Red Hat RHSA-2012:1284-01 2012-09-17
CentOS CESA-2012:1284 2012-09-17
Scientific Linux SL-spic-20120917 2012-09-17
Oracle ELSA-2012-1284 2012-09-17
Fedora FEDORA-2012-14107 2012-09-26
Mageia MGASA-2012-0278 2012-09-30
Fedora FEDORA-2012-14046 2012-10-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds