CVE-2012-4425

EUVD-2012-4360
libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable.  NOTE: it could be argued that this is a vulnerability in the applications that do not cleanse environment variables, not in libgio itself.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.9 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
Affected Products (NVD)
VendorProductVersion
freedesktopspice-gtk
-
gtklibgio
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
spice-gtk
bookworm
0.42-1
fixed
bullseye
0.39-1
fixed
sid
0.42-2.1
fixed
trixie
0.42-2.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
glib2.0
artful
not-affected
bionic
not-affected
cosmic
not-affected
disco
not-affected
eoan
not-affected
focal
not-affected
groovy
not-affected
hardy
ignored
hirsute
not-affected
lucid
ignored
natty
ignored
oneiric
ignored
precise
ignored
quantal
not-affected
raring
not-affected
saucy
not-affected
trusty
not-affected
utopic
not-affected
vivid
not-affected
wily
not-affected
xenial
not-affected
yakkety
not-affected
zesty
not-affected
spice-gtk
artful
not-affected
bionic
not-affected
cosmic
not-affected
disco
not-affected
eoan
not-affected
focal
not-affected
groovy
not-affected
hardy
dne
hirsute
not-affected
lucid
dne
natty
dne
oneiric
dne
precise
not-affected
quantal
ignored
raring
not-affected
saucy
not-affected
trusty
dne
utopic
not-affected
vivid
not-affected
wily
not-affected
xenial
not-affected
yakkety
not-affected
zesty
not-affected
Common Weakness Enumeration