Oval Definition:oval:org.mitre.oval:def:20906
Revision Date:2014-02-24Version:10
Title:RHSA-2012:1284: spice-gtk security update (Moderate)
Description:libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: it could be argued that this is a vulnerability in the applications that do not cleanse environment variables, not in libgio itself.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2012:1284
CVE-2012-4425
RHSA-2012:1284-01
Platform(s):CentOS Linux 6
Red Hat Enterprise Linux 6
Product(s):spice-gtk
Definition Synopsis
  • Redhat 6 or Centos 6 release
  • The operating system installed on the system is Red Hat Enterprise Linux 6
  • OR The operating system installed on the system is CentOS Linux 6.x
  • AND Packages section
  • spice-gtk-tools is earlier than 0:0.11-11.el6_3.1
  • OR spice-glib-devel is earlier than 0:0.11-11.el6_3.1
  • OR spice-glib is earlier than 0:0.11-11.el6_3.1
  • OR spice-gtk-python is earlier than 0:0.11-11.el6_3.1
  • OR spice-gtk is earlier than 0:0.11-11.el6_3.1
  • OR spice-gtk-devel is earlier than 0:0.11-11.el6_3.1
  • BACK