Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Red Hat ‘spice-gtk’模块本地安全绕过漏洞
Vulnerability Description
Red Hat spice-gtk是美国红帽(Red Hat)公司的一套能够让GObject和GTK连接到Spice服务器的工具。该工具提供了一套可与虚拟桌面和设备进行连接的解决方案。 spice-gtk中存在安全漏洞,该漏洞源于在通信期间polkit授权使用不安全的‘polkit_unix_process_new API’函数。本地攻击者可通过setuid或pkexec进程利用该漏洞绕过既定的访问限制。spice-gtk 0.14版本中存在漏洞,其他版本也可能受到影响。
CVSS Information
N/A
Vulnerability Type
N/A