Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-6655

Опубликовано: 15 июн. 2024
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK application from the current working directory.

Отчет

The severity of CVE-2024-6655 is considered moderate rather than important because it requires specific conditions to be exploited effectively. The vulnerability relies on the presence of a missing GTK module and requires the attacker to place a malicious library in the same directory as the vulnerable application. Furthermore, exploitation typically requires user interaction, such as running the application from a directory containing potentially malicious files. Unlike higher-severity issues, this vulnerability does not grant immediate remote code execution without user assistance, limiting its overall impact and likelihood of widespread exploitation.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10gtk3Not affected
Red Hat Enterprise Linux 10gtk4Not affected
Red Hat Enterprise Linux 6gtk2Out of support scope
Red Hat Enterprise Linux 7gtk2Out of support scope
Red Hat Enterprise Linux 7gtk3Out of support scope
Red Hat Enterprise Linux 8gimp:flatpak/gtk2Will not fix
Red Hat Enterprise Linux 8gtk2Will not fix
Red Hat Enterprise Linux 8inkscape:flatpak/gtk2Will not fix
Red Hat Enterprise Linux 9gtk2Will not fix
Red Hat Enterprise Linux 9gtk4Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2297098gtk3: gtk2: Library injection from CWD

EPSS

Процентиль: 24%
0.00076
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
11 месяцев назад

A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK application from the current working directory.

CVSS3: 7
nvd
11 месяцев назад

A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK application from the current working directory.

CVSS3: 7
msrc
11 месяцев назад

Описание отсутствует

CVSS3: 7
debian
11 месяцев назад

A flaw was found in the GTK library. Under certain conditions, it is p ...

suse-cvrf
5 месяцев назад

Security update for gtk3

EPSS

Процентиль: 24%
0.00076
Низкий

7 High

CVSS3