CVE-2011-0727

GNOME Display Manager (gdm) 2.x before 2.32.1 allows local users to change the ownership of arbitrary files via a symlink attack on a (1) dmrc or (2) face icon file under /var/cache/gdm/.
References
Link Resource
http://ftp.gnome.org/pub/GNOME/sources/gdm/2.32/gdm-2.32.1.news
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057333.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057931.html
http://mail.gnome.org/archives/gdm-list/2011-March/msg00020.html Patch
http://secunia.com/advisories/43714 Vendor Advisory
http://secunia.com/advisories/43854 Vendor Advisory
http://secunia.com/advisories/44021
http://securitytracker.com/id?1025264
http://www.debian.org/security/2011/dsa-2205
http://www.mandriva.com/security/advisories?name=MDVSA-2011:070
http://www.redhat.com/support/errata/RHSA-2011-0395.html
http://www.securityfocus.com/bid/47063
http://www.ubuntu.com/usn/USN-1099-1
http://www.vupen.com/english/advisories/2011/0786 Vendor Advisory
http://www.vupen.com/english/advisories/2011/0787 Vendor Advisory
http://www.vupen.com/english/advisories/2011/0797 Vendor Advisory
http://www.vupen.com/english/advisories/2011/0847
http://www.vupen.com/english/advisories/2011/0911
https://bugzilla.redhat.com/show_bug.cgi?id=688323 Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/66377
http://ftp.gnome.org/pub/GNOME/sources/gdm/2.32/gdm-2.32.1.news
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057333.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057931.html
http://mail.gnome.org/archives/gdm-list/2011-March/msg00020.html Patch
http://secunia.com/advisories/43714 Vendor Advisory
http://secunia.com/advisories/43854 Vendor Advisory
http://secunia.com/advisories/44021
http://securitytracker.com/id?1025264
http://www.debian.org/security/2011/dsa-2205
http://www.mandriva.com/security/advisories?name=MDVSA-2011:070
http://www.redhat.com/support/errata/RHSA-2011-0395.html
http://www.securityfocus.com/bid/47063
http://www.ubuntu.com/usn/USN-1099-1
http://www.vupen.com/english/advisories/2011/0786 Vendor Advisory
http://www.vupen.com/english/advisories/2011/0787 Vendor Advisory
http://www.vupen.com/english/advisories/2011/0797 Vendor Advisory
http://www.vupen.com/english/advisories/2011/0847
http://www.vupen.com/english/advisories/2011/0911
https://bugzilla.redhat.com/show_bug.cgi?id=688323 Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/66377
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnome:gdm:2.0:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.2:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.3:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.4:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.5:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.6:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.8:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.13:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.14:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.15:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.16:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.17:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.18:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.19:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.20:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.21:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.22:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.23:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.24:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.25:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.26:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.27:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.28:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.29:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.30:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.31:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdm:2.32:*:*:*:*:*:*:*

History

21 Nov 2024, 01:24

Type Values Removed Values Added
References () http://ftp.gnome.org/pub/GNOME/sources/gdm/2.32/gdm-2.32.1.news - () http://ftp.gnome.org/pub/GNOME/sources/gdm/2.32/gdm-2.32.1.news -
References () http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057333.html - () http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057333.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057931.html - () http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057931.html -
References () http://mail.gnome.org/archives/gdm-list/2011-March/msg00020.html - Patch () http://mail.gnome.org/archives/gdm-list/2011-March/msg00020.html - Patch
References () http://secunia.com/advisories/43714 - Vendor Advisory () http://secunia.com/advisories/43714 - Vendor Advisory
References () http://secunia.com/advisories/43854 - Vendor Advisory () http://secunia.com/advisories/43854 - Vendor Advisory
References () http://secunia.com/advisories/44021 - () http://secunia.com/advisories/44021 -
References () http://securitytracker.com/id?1025264 - () http://securitytracker.com/id?1025264 -
References () http://www.debian.org/security/2011/dsa-2205 - () http://www.debian.org/security/2011/dsa-2205 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2011:070 - () http://www.mandriva.com/security/advisories?name=MDVSA-2011:070 -
References () http://www.redhat.com/support/errata/RHSA-2011-0395.html - () http://www.redhat.com/support/errata/RHSA-2011-0395.html -
References () http://www.securityfocus.com/bid/47063 - () http://www.securityfocus.com/bid/47063 -
References () http://www.ubuntu.com/usn/USN-1099-1 - () http://www.ubuntu.com/usn/USN-1099-1 -
References () http://www.vupen.com/english/advisories/2011/0786 - Vendor Advisory () http://www.vupen.com/english/advisories/2011/0786 - Vendor Advisory
References () http://www.vupen.com/english/advisories/2011/0787 - Vendor Advisory () http://www.vupen.com/english/advisories/2011/0787 - Vendor Advisory
References () http://www.vupen.com/english/advisories/2011/0797 - Vendor Advisory () http://www.vupen.com/english/advisories/2011/0797 - Vendor Advisory
References () http://www.vupen.com/english/advisories/2011/0847 - () http://www.vupen.com/english/advisories/2011/0847 -
References () http://www.vupen.com/english/advisories/2011/0911 - () http://www.vupen.com/english/advisories/2011/0911 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=688323 - Patch () https://bugzilla.redhat.com/show_bug.cgi?id=688323 - Patch
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/66377 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/66377 -

Information

Published : 2011-03-31 22:55

Updated : 2024-11-21 01:24


NVD link : CVE-2011-0727

Mitre link : CVE-2011-0727

CVE.ORG link : CVE-2011-0727


JSON object : View

Products Affected

gnome

  • gdm
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')