LWN.net Logo

gdm: privilege escalation

Package(s):gdm CVE #(s):CVE-2011-0727
Created:March 29, 2011 Updated:April 8, 2011
Description: From the Red Hat advisory:

A race condition flaw was found in the way GDM handled the cache directories used to store users' dmrc and face icon files. A local attacker could use this flaw to trick GDM into changing the ownership of an arbitrary file via a symbolic link attack, allowing them to escalate their privileges.

Alerts:
Mandriva MDVSA-2011:070 2011-04-08
SUSE SUSE-SR:2011:006 2011-04-05
Fedora FEDORA-2011-4335 2011-03-29
openSUSE openSUSE-SU-2011:0275-1 2011-04-01
Ubuntu USN-1099-1 2011-03-30
Debian DSA-2205-1 2011-03-28
Red Hat RHSA-2011:0395-01 2011-03-28

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds