INFSA-2024:9184: gtk3 security update

Information about definition

Identificator: INFSA-2024:9184

Type: security

Release date: 2024-12-13 12:09:05 UTC

Information about package

The GTK+ library provides a multi-platform toolkit for creating graphical user interfaces. The gtk3 packages contain GTK+ version 3.

Vulnerabilities description

  • CVE-2024-6655

    A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK application from the current working directory.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
NIST — CVE-2024-6655
no information 7.0 no information
Critical, important, moderate, low

Updated packages