PT-2013-1177 · Red Hat+1 · Initscripts-Debuginfo+5

Vladz

·

Publicado

2013-09-05

·

Atualizado

2013-09-12

·

CVE-2013-4169

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions gdm versions prior to 2.21.1 gdm-docs versions 2.16.0 gdm-debuginfo versions 2.16.0 initscripts versions 8.45.42 initscripts-debuginfo versions 8.45.42
Description The issue allows local users to change permissions of arbitrary directories via a symlink attack on /tmp/.X11-unix/. This can lead to a disruption of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be carried out locally.
Recommendations For gdm versions prior to 2.21.1, update to version 2.21.1 or later to resolve the issue. For gdm-docs versions 2.16.0, consider disabling the vulnerable component until a patch is available. For gdm-debuginfo versions 2.16.0, restrict access to the vulnerable module to minimize the risk of exploitation. For initscripts versions 8.45.42, avoid using the vulnerable parameters in the affected API endpoint until the issue is resolved. For initscripts-debuginfo versions 8.45.42, as a temporary workaround, consider disabling the vulnerable function until a patch is available.

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06754
BDU:2015-06756
BDU:2015-06758
BDU:2015-06771
BDU:2015-06772
BDU:2015-09026
BDU:2015-09027
BDU:2015-09028
CVE-2013-4169
RHSA-2013:1213
RHSA-2013_1213

Produtos afetados

Red Hat
Gdm
Gdm-Debuginfo
Gdm-Docs
Initscripts
Initscripts-Debuginfo