Bugzilla – Bug 1228120
VUL-0: CVE-2024-6655: gtk2,gtk3,gtk4: library injection from current working directory
Last modified: 2024-07-19 11:09:30 UTC
A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK application from the current working directory. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-6655 https://bugzilla.redhat.com/show_bug.cgi?id=2297098 https://www.cve.org/CVERecord?id=CVE-2024-6655 https://access.redhat.com/security/cve/CVE-2024-6655 https://gitlab.gnome.org/GNOME/gtk/-/issues/6786 Patch: https://gitlab.gnome.org/GNOME/gtk/-/merge_requests/7361/diffs?commit_id=3bbf0b6176d42836d23c36a6ac410e807ec0a7a7