📦

libgio

Vendor: gtk

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 0 Remote Access
Total CVEs 3 Total Indexed
Avg. EPSS 1.09% Exploit Prob.
Latest CVE CVE-2012-4425 Sep 18

Security Vulnerability Index

Page 1 / 1
6.9 CVSS
CVE-2012-4425
Exploit Found

libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: it could be argued that this is a vulnerability in the applications that do not cleanse environment variables, not in libgio itself.

EPSS: 1.09%