4.3
CVSSv2

CVE-2006-6105

Published: 15/12/2006 Updated: 20/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 6.4 | Exploitability Score: 3.1
VMScore: 383
Vector: AV:L/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Format string vulnerability in the host chooser window (gdmchooser) in GNOME Foundation Display Manager (gdm) allows local users to execute arbitrary code via format string specifiers in a hostname, which are used in an error dialog.

Vulnerable Product Search on Vulmon Subscribe to Product

gnome gdm 2.16

gnome gdm 2.16.1

gnome gdm 2.14.1

gnome gdm 2.16.2

Vendor Advisories

A format string vulnerability was discovered in the gdmchooser component of the GNOME Display Manager By typing a specially crafted host name, local users could gain gdm user privileges, which could lead to further account information exposure ...