PT-2006-1015 · Debian+2 · Debian+2

Josh Bressers

+1

·

Publicado

2006-04-25

·

Atualizado

2018-10-03

·

CVE-2006-1057

CVSS v2.0

3.7

Baixa

VetorAV:L/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: gdm versions prior to 2.14.1
Description: A race condition issue exists in the daemon/slave.c component of gdm, allowing local users to gain privileges through a symlink attack when gdm performs chown and chgrp operations on the .ICEauthority file. Additionally, multiple vulnerabilities in the gdm package of Debian GNU/Linux may lead to breaches of confidentiality, integrity, and availability of protected information, potentially exploitable by local attackers.
Recommendations: For gdm versions prior to 2.14.1, update to version 2.14.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the .ICEauthority file to minimize the risk of exploitation.

Correção

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-03037
CVE-2006-1057
DSA-1040-1
RHSA-2007:0286
RHSA-2007_0286

Produtos afetados

Debian
Red Hat
Gdm