← Back

Spice Gtk

spice-gtk

Vendor: Freedesktop • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Freedesktop
Gtk
2Libgio
Spice Gtk
Apr 29, 2026
Sep 18, 2012
N/A· v4
N/A· v3
6.9 MEDIUM· v2
libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. N...Show more
libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: it could be argued that this is a vulnerability in the applications that do not cleanse environment variables, not in libgio itself.Show less