spice-gtk: Privilege escalation — GLSA 201406-29

A vulnerability in spice-gtk could allow local attackers to gain escalated privileges.

Affected packages

net-misc/spice-gtk on all architectures
Affected versions < 0.14
Unaffected versions >= 0.14

Background

spice-gtk is a set of GObject and Gtk objects for connecting to Spice servers and a client GUI.

Description

spice-gtk does not properly sanitize the DBUS_SYSTEM_BUS_ADDRESS environment variable.

Impact

A local attacker may be able to gain escalated privileges.

Workaround

There is no known workaround at this time.

Resolution

All spice-gtk users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=net-misc/spice-gtk-0.14"
 

References

Release date
June 26, 2014

Latest revision
June 26, 2014: 1

Severity
high

Exploitable
remote

Bugzilla entries