Upstream information
Description
libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: it could be argued that this is a vulnerability in the applications that do not cleanse environment variables, not in libgio itself.SUSE information
Overall state of this security issue: Does not affect SUSE products
This issue is currently rated as having moderate severity.
National Vulnerability Database | |
---|---|
Base Score | 6.9 |
Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Access Vector | Local |
Access Complexity | Medium |
Authentication | None |
Confidentiality Impact | Complete |
Integrity Impact | Complete |
Availability Impact | Complete |
List of released packages
Product(s) | Fixed package version(s) | References |
---|---|---|
SUSE Linux Enterprise Desktop 12 SP1 |
| Patchnames: SUSE Linux Enterprise Desktop 12 SP1 GA libspice-client-glib-2_0-8-0.29-1.4 SUSE Linux Enterprise Software Development Kit 12 SP1 GA spice-gtk-devel-0.29-1.4 |
SUSE Linux Enterprise Desktop 12 SP2 |
| Patchnames: SUSE Linux Enterprise Desktop 12 SP2 GA libspice-client-glib-2_0-8-0.31-7.2 SUSE Linux Enterprise Software Development Kit 12 SP2 GA spice-gtk-devel-0.31-7.2 |
SUSE Linux Enterprise Desktop 12 SP3 |
| Patchnames: SUSE Linux Enterprise Desktop 12 SP3 GA libspice-client-glib-2_0-8-0.33-1.33 SUSE Linux Enterprise Software Development Kit 12 SP3 GA spice-gtk-devel-0.33-1.33 |
SUSE Linux Enterprise Desktop 12 SP4 |
| Patchnames: SUSE Linux Enterprise Desktop 12 SP4 GA libspice-client-glib-2_0-8-0.33-3.6.1 SUSE Linux Enterprise Software Development Kit 12 SP4 GA spice-gtk-devel-0.33-3.6.1 |
SUSE Linux Enterprise Desktop 12 |
| Patchnames: SUSE Linux Enterprise Desktop 12 GA libspice-client-glib-2_0-8-0.25-3.4 SUSE Linux Enterprise Software Development Kit 12 GA spice-gtk-devel-0.25-3.4 |
SUSE Linux Enterprise Desktop 15 SUSE Linux Enterprise Module for Basesystem 15 |
| Patchnames: SUSE Linux Enterprise Module for Basesystem 15 GA libspice-client-glib-2_0-8-0.34-1.64 |
SUSE Linux Enterprise High Performance Computing 12 SP5 |
| Patchnames: SUSE Linux Enterprise High Performance Computing 12 SP5 GA libspice-client-glib-2_0-8-0.33-3.6.1 |
SUSE Linux Enterprise High Performance Computing 15 SUSE Linux Enterprise Server 15 SUSE Linux Enterprise Server for SAP Applications 15 |
| Patchnames: SUSE Linux Enterprise Module for Basesystem 15 GA libspice-client-glib-2_0-8-0.34-1.64 SUSE Linux Enterprise Module for Server Applications 15 GA spice-gtk-devel-0.34-1.64 |
SUSE Linux Enterprise Module for Server Applications 15 |
| Patchnames: SUSE Linux Enterprise Module for Server Applications 15 GA spice-gtk-devel-0.34-1.64 |
SUSE Linux Enterprise Server 12 SP1 |
| Patchnames: SUSE Linux Enterprise Server 12 SP1 GA libspice-client-glib-2_0-8-0.29-1.4 SUSE Linux Enterprise Software Development Kit 12 SP1 GA spice-gtk-devel-0.29-1.4 |
SUSE Linux Enterprise Server 12 SP2 |
| Patchnames: SUSE Linux Enterprise Server 12 SP2 GA libspice-client-glib-2_0-8-0.31-7.2 SUSE Linux Enterprise Software Development Kit 12 SP2 GA spice-gtk-devel-0.31-7.2 |
SUSE Linux Enterprise Server 12 SP3 |
| Patchnames: SUSE Linux Enterprise Server 12 SP3 GA libspice-client-glib-2_0-8-0.33-1.33 SUSE Linux Enterprise Software Development Kit 12 SP3 GA spice-gtk-devel-0.33-1.33 |
SUSE Linux Enterprise Server 12 SP4 |
| Patchnames: SUSE Linux Enterprise Server 12 SP4 GA libspice-client-glib-2_0-8-0.33-3.6.1 SUSE Linux Enterprise Software Development Kit 12 SP4 GA spice-gtk-devel-0.33-3.6.1 |
SUSE Linux Enterprise Server 12 SP5 |
| Patchnames: SUSE Linux Enterprise Server 12 SP5 GA libspice-client-glib-2_0-8-0.33-3.6.1 SUSE Linux Enterprise Software Development Kit 12 SP5 GA spice-gtk-devel-0.33-3.6.1 |
SUSE Linux Enterprise Server 12 |
| Patchnames: SUSE Linux Enterprise Server 12 GA libspice-client-glib-2_0-8-0.25-3.1 SUSE Linux Enterprise Software Development Kit 12 GA spice-gtk-devel-0.25-3.4 |
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 |
| Patchnames: SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 GA libspice-client-glib-2_0-8-0.31-7.2 |
SUSE Linux Enterprise Server for SAP Applications 12 SP1 SUSE Linux Enterprise Software Development Kit 12 SP1 |
| Patchnames: SUSE Linux Enterprise Software Development Kit 12 SP1 GA spice-gtk-devel-0.29-1.4 |
SUSE Linux Enterprise Server for SAP Applications 12 SP2 SUSE Linux Enterprise Software Development Kit 12 SP2 |
| Patchnames: SUSE Linux Enterprise Software Development Kit 12 SP2 GA spice-gtk-devel-0.31-7.2 |
SUSE Linux Enterprise Server for SAP Applications 12 SP3 SUSE Linux Enterprise Software Development Kit 12 SP3 |
| Patchnames: SUSE Linux Enterprise Software Development Kit 12 SP3 GA spice-gtk-devel-0.33-1.33 |
SUSE Linux Enterprise Server for SAP Applications 12 SP4 SUSE Linux Enterprise Software Development Kit 12 SP4 |
| Patchnames: SUSE Linux Enterprise Software Development Kit 12 SP4 GA spice-gtk-devel-0.33-3.6.1 |
SUSE Linux Enterprise Server for SAP Applications 12 SP5 SUSE Linux Enterprise Software Development Kit 12 SP5 |
| Patchnames: SUSE Linux Enterprise Software Development Kit 12 SP5 GA spice-gtk-devel-0.33-3.6.1 |
SUSE Linux Enterprise Server for SAP Applications 12 SUSE Linux Enterprise Software Development Kit 12 |
| Patchnames: SUSE Linux Enterprise Software Development Kit 12 GA spice-gtk-devel-0.25-3.4 |
openSUSE Leap 15.0 |
| Patchnames: openSUSE Leap 15.0 GA libspice-client-glib-2_0-8-0.34-lp150.1.14 |
openSUSE Tumbleweed |
| Patchnames: openSUSE-Tumbleweed-2024-10421 |
SUSE Timeline for this CVE
CVE page created: Fri Jun 28 13:06:19 2013CVE page last modified: Sat Jun 15 21:40:59 2024