PT-2006-1015 · Debian+2 · Debian+2
Josh Bressers
+1
·
Publicado
2006-04-25
·
Atualizado
2018-10-03
·
CVE-2006-1057
CVSS v2.0
3.7
Baixa
| Vetor | AV:L/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
gdm versions prior to 2.14.1
Description:
A race condition issue exists in the daemon/slave.c component of gdm, allowing local users to gain privileges through a symlink attack when gdm performs chown and chgrp operations on the .ICEauthority file. Additionally, multiple vulnerabilities in the gdm package of Debian GNU/Linux may lead to breaches of confidentiality, integrity, and availability of protected information, potentially exploitable by local attackers.
Recommendations:
For gdm versions prior to 2.14.1, update to version 2.14.1 or later to resolve the issue.
As a temporary workaround, consider restricting access to the .ICEauthority file to minimize the risk of exploitation.
Correção
Race Condition
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Debian
Red Hat
Gdm