6.9
CVSSv2

CVE-2011-0727

Published: 31/03/2011 Updated: 17/08/2017
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

GNOME Display Manager (gdm) 2.x prior to 2.32.1 allows local users to change the ownership of arbitrary files via a symlink attack on a (1) dmrc or (2) face icon file under /var/cache/gdm/.

Vulnerable Product Search on Vulmon Subscribe to Product

gnome gdm 2.2

gnome gdm 2.3

gnome gdm 2.16

gnome gdm 2.17

gnome gdm 2.0

gnome gdm 2.14

gnome gdm 2.15

gnome gdm 2.22

gnome gdm 2.23

gnome gdm 2.30

gnome gdm 2.31

gnome gdm 2.4

gnome gdm 2.5

gnome gdm 2.6

gnome gdm 2.18

gnome gdm 2.19

gnome gdm 2.26

gnome gdm 2.27

gnome gdm 2.8

gnome gdm 2.13

gnome gdm 2.20

gnome gdm 2.21

gnome gdm 2.28

gnome gdm 2.29

gnome gdm 2.24

gnome gdm 2.25

gnome gdm 2.32

Vendor Advisories

Debian Bug report logs - #639151 Local privilege escalation Package: lightdm; Maintainer for lightdm is Debian Xfce Maintainers <debian-xfce@listsdebianorg>; Source for lightdm is src:lightdm (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 24 Aug 2011 16:36:04 UTC Severity: grave ...
A GDM vulnerability allows local attackers to gain root privileges ...
Sebastian Krahmer discovered that GDM 3, the GNOME Display Manager, does not properly drop privileges when manipulating files related to the logged-in user As a result, local users can gain root privileges The oldstable distribution (lenny) does not contain a gdm3 package The gdm package is not affected by this issue For the stable distribution ...