Upstream information
Description
libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: it could be argued that this is a vulnerability in the applications that do not cleanse environment variables, not in libgio itself.SUSE information
Overall state of this security issue: Does not affect SUSE products
This issue is currently rated as having moderate severity.
| CVSS detail | National Vulnerability Database | 
|---|---|
| Base Score | 6.9 | 
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C | 
| Access Vector | Local | 
| Access Complexity | Medium | 
| Authentication | None | 
| Confidentiality Impact | Complete | 
| Integrity Impact | Complete | 
| Availability Impact | Complete | 
List of released packages
| Product(s) | Fixed package version(s) | References | 
|---|---|---|
| SUSE Linux Enterprise Desktop 12 SP1 | 
  |  Patchnames:  SUSE Linux Enterprise Desktop 12 SP1 GA libspice-client-glib-2_0-8-0.29-1.4 SUSE Linux Enterprise Software Development Kit 12 SP1 GA spice-gtk-devel-0.29-1.4  | 
| SUSE Linux Enterprise Desktop 12 SP2 | 
  |  Patchnames:  SUSE Linux Enterprise Desktop 12 SP2 GA libspice-client-glib-2_0-8-0.31-7.2 SUSE Linux Enterprise Software Development Kit 12 SP2 GA spice-gtk-devel-0.31-7.2  | 
| SUSE Linux Enterprise Desktop 12 SP3 | 
  |  Patchnames:  SUSE Linux Enterprise Desktop 12 SP3 GA libspice-client-glib-2_0-8-0.33-1.33 SUSE Linux Enterprise Software Development Kit 12 SP3 GA spice-gtk-devel-0.33-1.33  | 
| SUSE Linux Enterprise Desktop 12 SP4 | 
  |  Patchnames:  SUSE Linux Enterprise Desktop 12 SP4 GA libspice-client-glib-2_0-8-0.33-3.6.1 SUSE Linux Enterprise Software Development Kit 12 SP4 GA spice-gtk-devel-0.33-3.6.1  | 
| SUSE Linux Enterprise Desktop 12 | 
  |  Patchnames:  SUSE Linux Enterprise Desktop 12 GA libspice-client-glib-2_0-8-0.25-3.4 SUSE Linux Enterprise Software Development Kit 12 GA spice-gtk-devel-0.25-3.4  | 
| SUSE Linux Enterprise Desktop 15 SUSE Linux Enterprise Module for Basesystem 15  |  
  |  Patchnames:  SUSE Linux Enterprise Module for Basesystem 15 GA libspice-client-glib-2_0-8-0.34-1.64  | 
| SUSE Linux Enterprise High Performance Computing 12 SP5 | 
  |  Patchnames:  SUSE Linux Enterprise High Performance Computing 12 SP5 GA libspice-client-glib-2_0-8-0.33-3.6.1  | 
| SUSE Linux Enterprise High Performance Computing 15 SUSE Linux Enterprise Server 15 SUSE Linux Enterprise Server for SAP Applications 15  |  
  |  Patchnames:  SUSE Linux Enterprise Module for Basesystem 15 GA libspice-client-glib-2_0-8-0.34-1.64 SUSE Linux Enterprise Module for Server Applications 15 GA spice-gtk-devel-0.34-1.64  | 
| SUSE Linux Enterprise Module for Server Applications 15 | 
  |  Patchnames:  SUSE Linux Enterprise Module for Server Applications 15 GA spice-gtk-devel-0.34-1.64  | 
| SUSE Linux Enterprise Server 12 SP1 | 
  |  Patchnames:  SUSE Linux Enterprise Server 12 SP1 GA libspice-client-glib-2_0-8-0.29-1.4 SUSE Linux Enterprise Software Development Kit 12 SP1 GA spice-gtk-devel-0.29-1.4  | 
| SUSE Linux Enterprise Server 12 SP2 | 
  |  Patchnames:  SUSE Linux Enterprise Server 12 SP2 GA libspice-client-glib-2_0-8-0.31-7.2 SUSE Linux Enterprise Software Development Kit 12 SP2 GA spice-gtk-devel-0.31-7.2  | 
| SUSE Linux Enterprise Server 12 SP3 | 
  |  Patchnames:  SUSE Linux Enterprise Server 12 SP3 GA libspice-client-glib-2_0-8-0.33-1.33 SUSE Linux Enterprise Software Development Kit 12 SP3 GA spice-gtk-devel-0.33-1.33  | 
| SUSE Linux Enterprise Server 12 SP4 | 
  |  Patchnames:  SUSE Linux Enterprise Server 12 SP4 GA libspice-client-glib-2_0-8-0.33-3.6.1 SUSE Linux Enterprise Software Development Kit 12 SP4 GA spice-gtk-devel-0.33-3.6.1  | 
| SUSE Linux Enterprise Server 12 SP5 | 
  |  Patchnames:  SUSE Linux Enterprise Server 12 SP5 GA libspice-client-glib-2_0-8-0.33-3.6.1 SUSE Linux Enterprise Software Development Kit 12 SP5 GA spice-gtk-devel-0.33-3.6.1  | 
| SUSE Linux Enterprise Server 12 | 
  |  Patchnames:  SUSE Linux Enterprise Server 12 GA libspice-client-glib-2_0-8-0.25-3.1 SUSE Linux Enterprise Software Development Kit 12 GA spice-gtk-devel-0.25-3.4  | 
| SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 | 
  |  Patchnames:  SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 GA libspice-client-glib-2_0-8-0.31-7.2  | 
| SUSE Linux Enterprise Server for SAP Applications 12 SP1 SUSE Linux Enterprise Software Development Kit 12 SP1  |  
  |  Patchnames:  SUSE Linux Enterprise Software Development Kit 12 SP1 GA spice-gtk-devel-0.29-1.4  | 
| SUSE Linux Enterprise Server for SAP Applications 12 SP2 SUSE Linux Enterprise Software Development Kit 12 SP2  |  
  |  Patchnames:  SUSE Linux Enterprise Software Development Kit 12 SP2 GA spice-gtk-devel-0.31-7.2  | 
| SUSE Linux Enterprise Server for SAP Applications 12 SP3 SUSE Linux Enterprise Software Development Kit 12 SP3  |  
  |  Patchnames:  SUSE Linux Enterprise Software Development Kit 12 SP3 GA spice-gtk-devel-0.33-1.33  | 
| SUSE Linux Enterprise Server for SAP Applications 12 SP4 SUSE Linux Enterprise Software Development Kit 12 SP4  |  
  |  Patchnames:  SUSE Linux Enterprise Software Development Kit 12 SP4 GA spice-gtk-devel-0.33-3.6.1  | 
| SUSE Linux Enterprise Server for SAP Applications 12 SP5 | 
  |  Patchnames:  SUSE Linux Enterprise Server for SAP Applications 12 SP5 GA libspice-client-glib-2_0-8-0.33-3.6.1 SUSE Linux Enterprise Software Development Kit 12 SP5 GA spice-gtk-devel-0.33-3.6.1  | 
| SUSE Linux Enterprise Server for SAP Applications 12 SUSE Linux Enterprise Software Development Kit 12  |  
  |  Patchnames:  SUSE Linux Enterprise Software Development Kit 12 GA spice-gtk-devel-0.25-3.4  | 
| SUSE Linux Enterprise Software Development Kit 12 SP5 | 
  |  Patchnames:  SUSE Linux Enterprise Software Development Kit 12 SP5 GA spice-gtk-devel-0.33-3.6.1  | 
| openSUSE Leap 15.0 | 
  |  Patchnames:  openSUSE Leap 15.0 GA libspice-client-glib-2_0-8-0.34-lp150.1.14  | 
| openSUSE Tumbleweed | 
  |  Patchnames:  openSUSE-Tumbleweed-2024-10421  | 
SUSE Timeline for this CVE
CVE page created: Fri Jun 28 13:06:19 2013CVE page last modified: Sat Nov 1 19:51:35 2025