Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2001-0084

Overview

Vulnerability Score 7.2 7.2
CVE Id CVE-2001-0084
Last Modified 05 Sep 2008 04:23:13
Published 12 Feb 2001 12:00:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2001-0084

Summary

GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setuid/setgid program.

Vulnerable Systems

Application

  • Gtk%2b 1.2.8


References

BID - 2165

MISC - http://www.gtk.org/setuid.html

BUGTRAQ - 20010103 Claimed vulnerability in GTK_MODULES

BUGTRAQ - 20010102 gtk+ security hole.


Last Updated: 27 May 2016 10:36:08