ktsuss versions 1.4 and prior spawns the GTK interface to run as root. This can allow a local attacker to escalate privileges to root and use the "GTK_MODULES" environment variable to possibly execute arbitrary code.
Loading...
Loading...
Score 7.8 from GitHub Security Advisory (severity: HIGH) published 2022-04-22. NVD baseline CVSS 7.8; sources differ by 0.0.
ktsuss versions 1.4 and prior spawns the GTK interface to run as root. This can allow a local attacker to escalate privileges to root and use the "GTK_MODULES" environment variable to possibly execute arbitrary code.
November 19, 2019
November 21, 2024
See which npm, PyPI, Go, and Maven packages are affected by CVE-2011-2922
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.