First published: Fri Sep 14 2012(Updated: )
It was discovered that the spice-gtk setuid helper application, spice-client-glib-usb-acl-helper, did not clear the environment variables read by the libraries it uses. A local attacker could possibly use this flaw to escalate their privileges by setting specific environment variables before running the helper application. This flaw is similar to <a href="https://access.redhat.com/security/cve/CVE-2012-3524">CVE-2012-3524</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Freedesktop Spice-gtk | ||
Gtk Libgio |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.