CVE-2001-0084

GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setuid/setgid program.
References
Link Resource
http://archives.neohapsis.com/archives/bugtraq/2000-12/0498.html Exploit
http://archives.neohapsis.com/archives/bugtraq/2001-01/0027.html Third Party Advisory
http://www.gtk.org/setuid.html Third Party Advisory
http://www.securityfocus.com/bid/2165 Exploit Patch Third Party Advisory VDB Entry Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnome:gtk:1.2.8:*:*:*:*:*:*:*

History

03 Aug 2023, 17:15

Type Values Removed Values Added
CPE cpe:2.3:a:gtk:gtk\+:1.2.8:*:*:*:*:*:*:* cpe:2.3:a:gnome:gtk:1.2.8:*:*:*:*:*:*:*
First Time Gnome gtk
Gnome
References (MISC) http://www.gtk.org/setuid.html - (MISC) http://www.gtk.org/setuid.html - Third Party Advisory
References (BID) http://www.securityfocus.com/bid/2165 - Exploit, Patch, Vendor Advisory (BID) http://www.securityfocus.com/bid/2165 - Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
References (BUGTRAQ) http://archives.neohapsis.com/archives/bugtraq/2001-01/0027.html - (BUGTRAQ) http://archives.neohapsis.com/archives/bugtraq/2001-01/0027.html - Third Party Advisory

Information

Published : 2001-02-12 05:00

Updated : 2023-12-10 10:17


NVD link : CVE-2001-0084

Mitre link : CVE-2001-0084

CVE.ORG link : CVE-2001-0084


JSON object : View

Products Affected

gnome

  • gtk