Zero-friction vulnerability management platform
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux

CentOS Update for spice-glib CESA-2012:1284 centos6
Information
Severity
Severity
Family
Family
CVSSv2 Base
CVSSv2 Base
CVSSv2 Vector
CVSSv2 Vector
Solution Type
Solution Type
Created
Created
Modified
Modified
Summary
The remote host is missing an update for the 'spice-glib' package(s) announced via the referenced advisory.
Insight
Insight
The spice-gtk packages provide a GIMP Toolkit (GTK+) widget for SPICE (Simple Protocol for Independent Computing Environments) clients. Both Virtual Machine Manager and Virtual Machine Viewer can make use of this widget to access virtual machines using the SPICE protocol. It was discovered that the spice-gtk setuid helper application, spice-client-glib-usb-acl-helper, did not clear the environment variables read by the libraries it uses. A local attacker could possibly use this flaw to escalate their privileges by setting specific environment variables before running the helper application. (CVE-2012-4425) Red Hat would like to thank Sebastian Krahmer of the SUSE Security Team for reporting this issue. All users of spice-gtk are advised to upgrade to these updated packages, which contain a backported patch to correct this issue.
Affected Software
Affected Software
spice-glib on CentOS 6
Solution
Solution
Please install the updated packages.