|
|
| |
|
| |
gdm: uncontrolled access to local filesystem
| Package(s): | gdm |
CVE #(s): | CVE-2011-1709
|
| Created: | June 1, 2011 |
Updated: | June 7, 2011 |
| Description: |
From the Red Hat Bugzilla entry:
Henne Vogelsang discovered that, as of glib 2.28, it was possible to run the
default web browser (usually Firefox) in the GDM session, as the gdm user.
This resulted in uncontrolled access to the local file system and possibly
other resources as the gdm user. This is because glib 2.28 has changed the way
URI handlers are registered; while it used to be controlled via gconf settings,
it now is controlled via x-scheme-handler/<scheme> mime types (e.g.
x-scheme-handler/http).
|
| Alerts: |
|
( Log in to post comments)
|
|
|