PT-2013-1177 · Red Hat+1 · Initscripts-Debuginfo+5
Vladz
·
Publicado
2013-09-05
·
Atualizado
2013-09-12
·
CVE-2013-4169
CVSS v2.0
6.9
Média
| Vetor | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
gdm versions prior to 2.21.1
gdm-docs versions 2.16.0
gdm-debuginfo versions 2.16.0
initscripts versions 8.45.42
initscripts-debuginfo versions 8.45.42
Description
The issue allows local users to change permissions of arbitrary directories via a symlink attack on /tmp/.X11-unix/. This can lead to a disruption of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be carried out locally.
Recommendations
For gdm versions prior to 2.21.1, update to version 2.21.1 or later to resolve the issue.
For gdm-docs versions 2.16.0, consider disabling the vulnerable component until a patch is available.
For gdm-debuginfo versions 2.16.0, restrict access to the vulnerable module to minimize the risk of exploitation.
For initscripts versions 8.45.42, avoid using the vulnerable parameters in the affected API endpoint until the issue is resolved.
For initscripts-debuginfo versions 8.45.42, as a temporary workaround, consider disabling the vulnerable function until a patch is available.
Correção
Link Following
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat
Gdm
Gdm-Debuginfo
Gdm-Docs
Initscripts
Initscripts-Debuginfo