Executive Summary

Informations
Name MDVSA-2011:070 First vendor Publication 2011-04-08
Vendor Mandriva Last vendor Modification 2011-04-08
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:M/Au:N/C:C/I:C/A:C)
Cvss Base Score 6.9 Attack Range Local
Cvss Impact Score 10 Attack Complexity Medium
Cvss Expoit Score 3.4 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

A vulnerability has been found and corrected in gdm:

GNOME Display Manager (gdm) 2.x before 2.32.1 allows local users to change the ownership of arbitrary files via a symlink attack on a (1) dmrc or (2) face icon file under /var/cache/gdm/ (CVE-2011-0727).

The updated packages have been patched to correct this issue.

Original Source

Url : http://www.mandriva.com/security/advisories?name=MDVSA-2011:070

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-59 Improper Link Resolution Before File Access ('Link Following')

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:12826
 
Oval ID: oval:org.mitre.oval:def:12826
Title: DSA-2205-1 gdm3 -- privilege escalation
Description: Sebastian Krahmer discovered that the gdm3, the GNOME Desktop Manager, does not properly drop privileges when manipulating files related to the logged-in user. As a result, local users can gain root privileges. The oldstable distribution does not contain a gdm3 package. The gdm package is not affected by this issue.
Family: unix Class: patch
Reference(s): DSA-2205-1
CVE-2011-0727
Version: 5
Platform(s): Debian GNU/Linux 6.0
Debian GNU/kFreeBSD 6.0
Product(s): gdm3
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:13786
 
Oval ID: oval:org.mitre.oval:def:13786
Title: USN-1099-1 -- gdm vulnerability
Description: Sebastian Krahmer discovered that GDM did not properly drop privileges when handling the cache directories used to store users" dmrc and face icon files. This could allow a local attacker to change the ownership of arbitrary files, thereby gaining root privileges.
Family: unix Class: patch
Reference(s): USN-1099-1
CVE-2011-0727
Version: 5
Platform(s): Ubuntu 10.10
Ubuntu 9.10
Ubuntu 10.04
Product(s): gdm
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:21930
 
Oval ID: oval:org.mitre.oval:def:21930
Title: RHSA-2011:0395: gdm security update (Moderate)
Description: GNOME Display Manager (gdm) 2.x before 2.32.1 allows local users to change the ownership of arbitrary files via a symlink attack on a (1) dmrc or (2) face icon file under /var/cache/gdm/.
Family: unix Class: patch
Reference(s): RHSA-2011:0395-01
CVE-2011-0727
Version: 4
Platform(s): Red Hat Enterprise Linux 6
Product(s): gdm
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:23685
 
Oval ID: oval:org.mitre.oval:def:23685
Title: ELSA-2011:0395: gdm security update (Moderate)
Description: GNOME Display Manager (gdm) 2.x before 2.32.1 allows local users to change the ownership of arbitrary files via a symlink attack on a (1) dmrc or (2) face icon file under /var/cache/gdm/.
Family: unix Class: patch
Reference(s): ELSA-2011:0395-01
CVE-2011-0727
Version: 6
Platform(s): Oracle Linux 6
Product(s): gdm
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:27397
 
Oval ID: oval:org.mitre.oval:def:27397
Title: DEPRECATED: ELSA-2011-0395 -- gdm security update (moderate)
Description: [2.30.4-21.0.2.el6_0.1] - Added oracle-enterprise.patch to show oracle-release contents. [2.30.4-21.1] - Fix CVE-2011-0727
Family: unix Class: patch
Reference(s): ELSA-2011-0395
CVE-2011-0727
Version: 4
Platform(s): Oracle Linux 6
Product(s): gdm
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 27

OpenVAS Exploits

Date Description
2012-06-06 Name : RedHat Update for gdm RHSA-2011:0395-01
File : nvt/gb_RHSA-2011_0395-01_gdm.nasl
2011-05-12 Name : Debian Security Advisory DSA 2205-1 (gdm3)
File : nvt/deb_2205_1.nasl
2011-05-12 Name : FreeBSD Ports: gdm
File : nvt/freebsd_gdm.nasl
2011-04-19 Name : Fedora Update for gdm FEDORA-2011-4351
File : nvt/gb_fedora_2011_4351_gdm_fc13.nasl
2011-04-11 Name : Mandriva Update for gdm MDVSA-2011:070 (gdm)
File : nvt/gb_mandriva_MDVSA_2011_070.nasl
2011-04-06 Name : Fedora Update for gdm FEDORA-2011-4335
File : nvt/gb_fedora_2011_4335_gdm_fc14.nasl
2011-04-01 Name : Ubuntu Update for gdm vulnerability USN-1099-1
File : nvt/gb_ubuntu_USN_1099_1.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
72551 GNOME Display Manager (gdm) /var/cache/gdm/ Multiple File Symlink Local Privi...

Nessus® Vulnerability Scanner

Date Description
2014-12-15 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201412-09.nasl - Type : ACT_GATHER_INFO
2014-06-13 Name : The remote openSUSE host is missing a security update.
File : suse_11_3_gdm-110330.nasl - Type : ACT_GATHER_INFO
2014-06-13 Name : The remote openSUSE host is missing a security update.
File : suse_11_4_gdm-110330.nasl - Type : ACT_GATHER_INFO
2013-07-12 Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2011-0395.nasl - Type : ACT_GATHER_INFO
2012-08-01 Name : The remote Scientific Linux host is missing one or more security updates.
File : sl_20110329_gdm_on_SL6_x.nasl - Type : ACT_GATHER_INFO
2011-04-15 Name : The remote Fedora host is missing a security update.
File : fedora_2011-4351.nasl - Type : ACT_GATHER_INFO
2011-04-11 Name : The remote Mandriva Linux host is missing one or more security updates.
File : mandriva_MDVSA-2011-070.nasl - Type : ACT_GATHER_INFO
2011-04-04 Name : The remote Fedora host is missing a security update.
File : fedora_2011-4335.nasl - Type : ACT_GATHER_INFO
2011-03-31 Name : The remote Ubuntu host is missing a security-related patch.
File : ubuntu_USN-1099-1.nasl - Type : ACT_GATHER_INFO
2011-03-30 Name : The remote FreeBSD host is missing a security-related update.
File : freebsd_pkg_c6fbd44759ed11e08d040015f2db7bde.nasl - Type : ACT_GATHER_INFO
2011-03-29 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-2205.nasl - Type : ACT_GATHER_INFO
2011-03-29 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2011-0395.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2014-02-17 11:42:11
  • Multiple Updates