CVE-2012-4425

libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable.  NOTE: it could be argued that this is a vulnerability in the applications that do not cleanse environment variables, not in libgio itself.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.9 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
Affected Products (NVD)
VendorProductVersion
freedesktopspice-gtk
-
gtklibgio
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
spice-gtk
bookworm
0.42-1
fixed
bullseye
0.39-1
fixed
sid
0.42-2.1
fixed
trixie
0.42-2.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
glib2.0
artful
not-affected
bionic
not-affected
cosmic
not-affected
disco
not-affected
eoan
not-affected
focal
not-affected
groovy
not-affected
hardy
ignored
hirsute
not-affected
lucid
ignored
natty
ignored
oneiric
ignored
precise
ignored
quantal
not-affected
raring
not-affected
saucy
not-affected
trusty
not-affected
utopic
not-affected
vivid
not-affected
wily
not-affected
xenial
not-affected
yakkety
not-affected
zesty
not-affected
spice-gtk
artful
not-affected
bionic
not-affected
cosmic
not-affected
disco
not-affected
eoan
not-affected
focal
not-affected
groovy
not-affected
hardy
dne
hirsute
not-affected
lucid
dne
natty
dne
oneiric
dne
precise
not-affected
quantal
ignored
raring
not-affected
saucy
not-affected
trusty
dne
utopic
not-affected
vivid
not-affected
wily
not-affected
xenial
not-affected
yakkety
not-affected
zesty
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libspice-client-glib-2_0-8
suse enterprise desktop 15
0.34-1.64
fixed
suse enterprise sap 12 SP5
0.33-3.6.1
fixed
suse enterprise sap 15
0.34-1.64
fixed
suse enterprise server 12 SP2
0.31-7.2
fixed
suse enterprise server 12 SP4
0.33-3.6.1
fixed
suse enterprise server 12 SP5
0.33-3.6.1
fixed
suse enterprise server 15
0.34-1.64
fixed
libspice-client-glib-helper
suse enterprise desktop 15
0.34-1.64
fixed
suse enterprise sap 12 SP5
0.33-3.6.1
fixed
suse enterprise sap 15
0.34-1.64
fixed
suse enterprise server 12 SP2
0.31-7.2
fixed
suse enterprise server 12 SP4
0.33-3.6.1
fixed
suse enterprise server 12 SP5
0.33-3.6.1
fixed
suse enterprise server 15
0.34-1.64
fixed
libspice-client-gtk-2_0-4
suse enterprise server 12 SP2
0.31-7.2
fixed
libspice-client-gtk-3_0-4
suse enterprise server 12 SP2
0.31-7.2
fixed
libspice-client-gtk-3_0-5
suse enterprise desktop 15
0.34-1.64
fixed
suse enterprise sap 12 SP5
0.33-3.6.1
fixed
suse enterprise sap 15
0.34-1.64
fixed
suse enterprise server 12 SP4
0.33-3.6.1
fixed
suse enterprise server 12 SP5
0.33-3.6.1
fixed
suse enterprise server 15
0.34-1.64
fixed
libspice-controller0
suse enterprise desktop 15
0.34-1.64
fixed
suse enterprise sap 12 SP5
0.33-3.6.1
fixed
suse enterprise sap 15
0.34-1.64
fixed
suse enterprise server 12 SP2
0.31-7.2
fixed
suse enterprise server 12 SP4
0.33-3.6.1
fixed
suse enterprise server 12 SP5
0.33-3.6.1
fixed
suse enterprise server 15
0.34-1.64
fixed
spice-gtk-devel
suse enterprise sap 15
0.34-1.64
fixed
suse enterprise server 15
0.34-1.64
fixed
typelib-1_0-SpiceClientGlib-2_0
suse enterprise sap 12 SP5
0.33-3.6.1
fixed
suse enterprise sap 15
0.34-1.64
fixed
suse enterprise server 12 SP2
0.31-7.2
fixed
suse enterprise server 12 SP4
0.33-3.6.1
fixed
suse enterprise server 12 SP5
0.33-3.6.1
fixed
suse enterprise server 15
0.34-1.64
fixed
typelib-1_0-SpiceClientGtk-3_0
suse enterprise sap 12 SP5
0.33-3.6.1
fixed
suse enterprise sap 15
0.34-1.64
fixed
suse enterprise server 12 SP2
0.31-7.2
fixed
suse enterprise server 12 SP4
0.33-3.6.1
fixed
suse enterprise server 12 SP5
0.33-3.6.1
fixed
suse enterprise server 15
0.34-1.64
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
spice-glib
RHEL 6
0:0.11-11.el6_3.1
fixed
spice-glib-devel
RHEL 6
0:0.11-11.el6_3.1
fixed
spice-gtk
RHEL 6
0:0.11-11.el6_3.1
fixed
spice-gtk-devel
RHEL 6
0:0.11-11.el6_3.1
fixed
spice-gtk-python
RHEL 6
0:0.11-11.el6_3.1
fixed
spice-gtk-tools
RHEL 6
0:0.11-11.el6_3.1
fixed
Common Weakness Enumeration