Logo
componentspice-gtk
Name
spice-gtk
Version
0.42
Type
library
Description
A Gtk client and libraries for SPICE remote desktop servers.
Licenses
LGPL-2.1-only & BSD-3-Clause & GPL-2.0-only
PURL
-
CPE
cpe:2.3:*:*:spice-gtk:0.42:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
0.42

Vulnerabilities#


Name
Analysis
Description
Not Affected
libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: it could be argued that this is a vulnerability in the applications that do not cleanse environment variables, not in libgio itself.