spice-gtk: Privilege escalation A vulnerability in spice-gtk could allow local attackers to gain escalated privileges. spice-gtk 2014-06-26 2014-06-26 435694 remote 0.14 0.14

spice-gtk is a set of GObject and Gtk objects for connecting to Spice servers and a client GUI.

spice-gtk does not properly sanitize the DBUS_SYSTEM_BUS_ADDRESS environment variable.

A local attacker may be able to gain escalated privileges.

There is no known workaround at this time.

All spice-gtk users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-misc/spice-gtk-0.14"
CVE-2012-4425 craig ackle