CVE-2012-4425
Publication date 18 September 2012
Last updated 24 July 2024
Ubuntu priority
libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: it could be argued that this is a vulnerability in the applications that do not cleanse environment variables, not in libgio itself.
Status
Package | Ubuntu Release | Status |
---|---|---|
glib2.0 | ||
20.04 LTS focal |
Not affected
|
|
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
|
spice-gtk | ||
20.04 LTS focal |
Not affected
|
|
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |
Notes
mdeslaur
RedHat has fixed this in spice-gtk itself. Setting as low, since spice-gtk is probably one of the only apps to do this.