PT-2011-3489 · Gnome · Libgnomesu

Published

2011-07-07

·

Updated

2024-06-15

·

CVE-2011-1946

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libgnomesu version 1.0.0
Description The issue allows local users to gain privileges by leveraging access to two unprivileged user accounts and running many processes under one of these accounts. This is due to the gnomesu-pam-backend in libgnomesu printing an error message but proceeding with the non-error code path upon failure of the setgid or setuid function.
Recommendations For libgnomesu version 1.0.0, consider restricting access to the gnomesu-pam-backend to minimize the risk of exploitation. As a temporary workaround, avoid using the setgid or setuid functions in sensitive operations until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1946
OPENSUSE-SU-2024:10076-1

Affected Products

Libgnomesu