CVE-2012-4425

Freedesktop Spice-gtk - Access Control

Title source: rule

Description

libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: it could be argued that this is a vulnerability in the applications that do not cleanse environment variables, not in libgio itself.

Exploits (1)

exploitdb WORKING POC
by Sebastian Krahmer · clocallinux
https://www.exploit-db.com/exploits/21323

Scores

EPSS 0.0052
EPSS Percentile 66.8%

Details

CWE
CWE-264
Status published
Products (2)
freedesktop/spice-gtk
gtk/libgio
Published Sep 18, 2012
Tracked Since Feb 18, 2026