LWN.net Logo

gdm: uncontrolled access to local filesystem

Package(s):gdm CVE #(s):CVE-2011-1709
Created:June 1, 2011 Updated:June 7, 2011
Description:

From the Red Hat Bugzilla entry:

Henne Vogelsang discovered that, as of glib 2.28, it was possible to run the default web browser (usually Firefox) in the GDM session, as the gdm user. This resulted in uncontrolled access to the local file system and possibly other resources as the gdm user. This is because glib 2.28 has changed the way URI handlers are registered; while it used to be controlled via gconf settings, it now is controlled via x-scheme-handler/<scheme> mime types (e.g. x-scheme-handler/http).

Alerts:
Fedora FEDORA-2011-7822 2011-06-03
Ubuntu USN-1142-1 2011-06-01
openSUSE openSUSE-SU-2011:0581-1 2011-06-01

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds