CVE-2024-6655

A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK application from the current working directory.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7 HIGH
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
redhatCNA
7 HIGH
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
CVEADP
---
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 23%
Debian logo
Debian Releases
Debian Product
Codename
gtk+2.0
bullseye
2.24.33-2+deb11u1
fixed
bookworm
2.24.33-2+deb12u1
fixed
sid
2.24.33-7
fixed
trixie
2.24.33-7
fixed
gtk+3.0
bullseye
3.24.24-4+deb11u4
fixed
bookworm
3.24.38-2~deb12u3
fixed
sid
3.24.49-3
fixed
trixie
3.24.49-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gtk+2.0
plucky
Fixed 2.24.33-5ubuntu1
released
oracular
Fixed 2.24.33-5ubuntu1
released
noble
Fixed 2.24.33-4ubuntu1.1
released
mantic
ignored
jammy
Fixed 2.24.33-2ubuntu2.1
released
focal
Fixed 2.24.32-4ubuntu4.1
released
bionic
needs-triage
xenial
needs-triage
gtk+3.0
plucky
Fixed 3.24.43-1ubuntu1
released
oracular
Fixed 3.24.43-1ubuntu1
released
noble
Fixed 3.24.41-4ubuntu1.1
released
mantic
ignored
jammy
Fixed 3.24.33-1ubuntu2.2
released
focal
Fixed 3.24.20-0ubuntu1.2
released
bionic
needs-triage
xenial
needs-triage