oval:org.mitre.oval:def:23989

Definition Id: oval:org.mitre.oval:def:23989
 
Oval ID: oval:org.mitre.oval:def:23989
Title: ELSA-2012:1284: spice-gtk security update (Moderate)
Description: libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: it could be argued that this is a vulnerability in the applications that do not cleanse environment variables, not in libgio itself.
Family: unix Class: patch
Reference(s): ELSA-2012:1284-01
CVE-2012-4425
Version: 6
Platform(s): Oracle Linux 6
Product(s): spice-gtk
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:16594
 
Oval ID: oval:org.mitre.oval:def:16594
Title: Oracle Linux 6.x
Description: The operating system installed on the system is Oracle Linux 6.x
Family: unix Class: inventory
Reference(s): cpe:/o:oracle:linux:6
Version: 5
Platform(s): Oracle Linux 6
Product(s):
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:23989