Loading...
Loading...
libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: it could be argued that this is a vulnerability in the applications that do not cleanse environment variables, not in libgio itself.
September 18, 2012
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2012-4425
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.