https://seclists.org/oss-sec/2024/q3/256: CVE-2024-6655 Library injection from CWD in GTK-2/GTK-3
Published Sep 9, 2024
·Updated
Affected Software
2 affected components
GTK GTK>3.24.43
GTK GTK-2
Frequently Asked Questions
1
What is the severity of CVE-2024-6655?
CVE-2024-6655 is classified as a high-severity vulnerability due to its potential to allow library injection from the current working directory.
2
How do I fix CVE-2024-6655?
To fix CVE-2024-6655, ensure that you update to the latest version of GTK that includes the necessary security patches.
3
What versions of GTK are affected by CVE-2024-6655?
CVE-2024-6655 affects applications built on GTK-2 and GTK-3.
4
What is the impact of CVE-2024-6655 on applications?
CVE-2024-6655 could allow an attacker to execute arbitrary code through library injection, compromising the application's security.
5
Is CVE-2024-6655 specific to any operating system?
CVE-2024-6655 is cross-platform, affecting any OS running applications that utilize GTK-2 or GTK-3.