PT-2011-3489 · Gnome · Libgnomesu
Published
2011-07-07
·
Updated
2024-06-15
·
CVE-2011-1946
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
libgnomesu version 1.0.0
Description
The issue allows local users to gain privileges by leveraging access to two unprivileged user accounts and running many processes under one of these accounts. This is due to the gnomesu-pam-backend in libgnomesu printing an error message but proceeding with the non-error code path upon failure of the
setgid or setuid function.Recommendations
For libgnomesu version 1.0.0, consider restricting access to the gnomesu-pam-backend to minimize the risk of exploitation. As a temporary workaround, avoid using the setgid or setuid functions in sensitive operations until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libgnomesu