PT-2006-1054 · Gnome · Gnome Gdm

Vã­Ctor Daniel

·

Publicado

2006-06-09

·

Atualizado

2018-10-03

·

CVE-2006-2452

CVSS v2.0

3.7

Baixa

VetorAV:L/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: GNOME GDM versions 2.8 through 2.15
Description: The issue allows local users to access the "Configure Login Manager" functionality using their own password instead of the root password when the "face browser" feature is enabled. This can be leveraged to gain additional privileges. Exploitation of the vulnerability may lead to a breach of confidentiality, integrity, and availability of protected information, and it can be exploited locally.
Recommendations: For GNOME GDM versions 2.8 through 2.15, consider disabling the "face browser" feature to prevent unauthorized access to the "Configure Login Manager" functionality until a patch is available. Restrict access to the "Configure Login Manager" to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-09511
CVE-2006-2452

Produtos afetados

Gnome Gdm