Related Vulnerabilities: CVE-2020-16125  

gdm before 3.38.2 can be tricked into launching gnome-initial-setup, enabling an unprivileged user to create a new user account for themselves. The new account is a member of the sudo group, so this enables the unprivileged user to obtain admin privileges.

Severity High

Remote No

Type Privilege escalation

Description

gdm before 3.38.2 can be tricked into launching gnome-initial-setup, enabling an unprivileged user to create a new user account for themselves. The new account is a member of the sudo group, so this enables the unprivileged user to obtain admin privileges.

AVG-1264 gdm 3.38.1-3 3.38.2-1 High Fixed

10 Nov 2020 ASA-202011-5 AVG-1264 gdm High privilege escalation

https://gitlab.gnome.org/GNOME/gdm/-/issues/642