A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK application from the current working directory. (CVE-2024-6655) References: . MGASA-2024-0312 - Updated gtk+2.0 and gtk+3.0 packages fix security vulnerability Publication date: 25 Sep 2024 URL: https://advisories.mageia.org/MGASA-2024-0312.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-6655 A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK application from the current working directory. (CVE-2024-6655) References: - https://bugs.mageia.org/show_bug.cgi?id=33409 - https://ubuntu.com/security/notices/USN-6899-1 - https://www.cve.org/CVERecord?id=CVE-2024-6655 SRPMS: - 9/core/gtk+2.0-2.24.33-5.1.mga9 - 9/core/gtk+3.0-3.24.38-1.1.mga9 . Mageia Announcement: Revised gtk+2.0 and gtk+3.0 packages resolve security vulnerability related to library injection problems.. gtk vulnerability, Mageia updates, library security, application injection, software patching. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.