CVE-2001-0084: High severity Gnome GTK vulnerability
Published Feb 2, 2001
·Updated
GTK+ library allows local users to specify arbitrary modules via the GTKMODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setuid/setgid program.
Affected Software
2 affected components
Gnome GTK=1.2.8
GTK Gtk\+=1.2.8
Remediation
Patch Available
Event History
Feb 2, 2001
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0084?
CVE-2001-0084 is classified as a local privilege escalation vulnerability.
2
How do I fix CVE-2001-0084?
To fix CVE-2001-0084, consider removing the setuid/setgid permissions from programs that utilize the GTK+ library.
3
Which versions of GTK+ are affected by CVE-2001-0084?
CVE-2001-0084 specifically affects GTK+ version 1.2.8.
4
Can CVE-2001-0084 be exploited remotely?
CVE-2001-0084 cannot be exploited remotely as it requires local user access.
5
What impact does CVE-2001-0084 have on system security?
CVE-2001-0084 could allow local users to gain elevated privileges on systems running vulnerable GTK+ applications.