PT-2013-1177 · Red Hat+1 · Initscripts-Debuginfo+5

Vladz

·

Published

2013-09-05

·

Updated

2013-09-12

·

CVE-2013-4169

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions gdm versions prior to 2.21.1 gdm-docs versions 2.16.0 gdm-debuginfo versions 2.16.0 initscripts versions 8.45.42 initscripts-debuginfo versions 8.45.42
Description The issue allows local users to change permissions of arbitrary directories via a symlink attack on /tmp/.X11-unix/. This can lead to a disruption of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be carried out locally.
Recommendations For gdm versions prior to 2.21.1, update to version 2.21.1 or later to resolve the issue. For gdm-docs versions 2.16.0, consider disabling the vulnerable component until a patch is available. For gdm-debuginfo versions 2.16.0, restrict access to the vulnerable module to minimize the risk of exploitation. For initscripts versions 8.45.42, avoid using the vulnerable parameters in the affected API endpoint until the issue is resolved. For initscripts-debuginfo versions 8.45.42, as a temporary workaround, consider disabling the vulnerable function until a patch is available.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06754
BDU:2015-06756
BDU:2015-06758
BDU:2015-06771
BDU:2015-06772
BDU:2015-09026
BDU:2015-09027
BDU:2015-09028
CVE-2013-4169
RHSA-2013:1213
RHSA-2013_1213

Affected Products

Red Hat
Gdm
Gdm-Debuginfo
Gdm-Docs
Initscripts
Initscripts-Debuginfo