PT-2011-1040 · Gnome+1 · Gdm-Libs+7

Sebastian Krahmer

·

Publicado

2011-03-28

·

Atualizado

2017-08-17

·

CVE-2011-0727

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GNOME Display Manager (gdm) versions 2.x through 2.32.0 gdm-user-switch-applet version 2.30.4 gdm-plugin-fingerprint version 2.30.4 gdm version 2.30.4 gdm-libs version 2.30.4 gdm-plugin-smartcard version 2.30.4 gdm-debuginfo version 2.30.4
Description The issue allows local users to change the ownership of arbitrary files via a symlink attack on a dmrc or face icon file under /var/cache/gdm/. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be carried out locally.
Recommendations For GNOME Display Manager (gdm) versions 2.x through 2.32.0, update to version 2.32.1 or later. For gdm-user-switch-applet version 2.30.4, consider disabling the use of this applet until a patch is available. For gdm-plugin-fingerprint version 2.30.4, restrict access to the fingerprint plugin to minimize the risk of exploitation. For gdm version 2.30.4, gdm-libs version 2.30.4, gdm-plugin-smartcard version 2.30.4, and gdm-debuginfo version 2.30.4, update to a newer version that contains a fix for this issue, if available. At the moment, there is no information about a newer version that contains a fix for gdm3.

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-02916
BDU:2015-06755
BDU:2015-06757
BDU:2015-06759
BDU:2015-06760
BDU:2015-06761
BDU:2015-06762
CVE-2011-0727
DSA-2205-1
RHSA-2011:0395
RHSA-2011_0395

Produtos afetados

Gnome Display Manager
Red Hat
Gdm
Gdm-Debuginfo
Gdm-Libs
Gdm-Plugin-Fingerprint
Gdm-Plugin-Smartcard
Gdm-User-Switch-Applet