fkie_cve-2011-0727
Vulnerability from fkie_nvd
Published
2011-03-31 22:55
Modified
2025-04-11 00:51
Severity ?
Summary
GNOME Display Manager (gdm) 2.x before 2.32.1 allows local users to change the ownership of arbitrary files via a symlink attack on a (1) dmrc or (2) face icon file under /var/cache/gdm/.
References
security@ubuntu.comhttp://ftp.gnome.org/pub/GNOME/sources/gdm/2.32/gdm-2.32.1.news
security@ubuntu.comhttp://lists.fedoraproject.org/pipermail/package-announce/2011-April/057333.html
security@ubuntu.comhttp://lists.fedoraproject.org/pipermail/package-announce/2011-April/057931.html
security@ubuntu.comhttp://mail.gnome.org/archives/gdm-list/2011-March/msg00020.htmlPatch
security@ubuntu.comhttp://secunia.com/advisories/43714Vendor Advisory
security@ubuntu.comhttp://secunia.com/advisories/43854Vendor Advisory
security@ubuntu.comhttp://secunia.com/advisories/44021
security@ubuntu.comhttp://securitytracker.com/id?1025264
security@ubuntu.comhttp://www.debian.org/security/2011/dsa-2205
security@ubuntu.comhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:070
security@ubuntu.comhttp://www.redhat.com/support/errata/RHSA-2011-0395.html
security@ubuntu.comhttp://www.securityfocus.com/bid/47063
security@ubuntu.comhttp://www.ubuntu.com/usn/USN-1099-1
security@ubuntu.comhttp://www.vupen.com/english/advisories/2011/0786Vendor Advisory
security@ubuntu.comhttp://www.vupen.com/english/advisories/2011/0787Vendor Advisory
security@ubuntu.comhttp://www.vupen.com/english/advisories/2011/0797Vendor Advisory
security@ubuntu.comhttp://www.vupen.com/english/advisories/2011/0847
security@ubuntu.comhttp://www.vupen.com/english/advisories/2011/0911
security@ubuntu.comhttps://bugzilla.redhat.com/show_bug.cgi?id=688323Patch
security@ubuntu.comhttps://exchange.xforce.ibmcloud.com/vulnerabilities/66377
af854a3a-2127-422b-91ae-364da2661108http://ftp.gnome.org/pub/GNOME/sources/gdm/2.32/gdm-2.32.1.news
af854a3a-2127-422b-91ae-364da2661108http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057333.html
af854a3a-2127-422b-91ae-364da2661108http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057931.html
af854a3a-2127-422b-91ae-364da2661108http://mail.gnome.org/archives/gdm-list/2011-March/msg00020.htmlPatch
af854a3a-2127-422b-91ae-364da2661108http://secunia.com/advisories/43714Vendor Advisory
af854a3a-2127-422b-91ae-364da2661108http://secunia.com/advisories/43854Vendor Advisory
af854a3a-2127-422b-91ae-364da2661108http://secunia.com/advisories/44021
af854a3a-2127-422b-91ae-364da2661108http://securitytracker.com/id?1025264
af854a3a-2127-422b-91ae-364da2661108http://www.debian.org/security/2011/dsa-2205
af854a3a-2127-422b-91ae-364da2661108http://www.mandriva.com/security/advisories?name=MDVSA-2011:070
af854a3a-2127-422b-91ae-364da2661108http://www.redhat.com/support/errata/RHSA-2011-0395.html
af854a3a-2127-422b-91ae-364da2661108http://www.securityfocus.com/bid/47063
af854a3a-2127-422b-91ae-364da2661108http://www.ubuntu.com/usn/USN-1099-1
af854a3a-2127-422b-91ae-364da2661108http://www.vupen.com/english/advisories/2011/0786Vendor Advisory
af854a3a-2127-422b-91ae-364da2661108http://www.vupen.com/english/advisories/2011/0787Vendor Advisory
af854a3a-2127-422b-91ae-364da2661108http://www.vupen.com/english/advisories/2011/0797Vendor Advisory
af854a3a-2127-422b-91ae-364da2661108http://www.vupen.com/english/advisories/2011/0847
af854a3a-2127-422b-91ae-364da2661108http://www.vupen.com/english/advisories/2011/0911
af854a3a-2127-422b-91ae-364da2661108https://bugzilla.redhat.com/show_bug.cgi?id=688323Patch
af854a3a-2127-422b-91ae-364da2661108https://exchange.xforce.ibmcloud.com/vulnerabilities/66377
Impacted products
Vendor Product Version
gnome gdm 2.0
gnome gdm 2.2
gnome gdm 2.3
gnome gdm 2.4
gnome gdm 2.5
gnome gdm 2.6
gnome gdm 2.8
gnome gdm 2.13
gnome gdm 2.14
gnome gdm 2.15
gnome gdm 2.16
gnome gdm 2.17
gnome gdm 2.18
gnome gdm 2.19
gnome gdm 2.20
gnome gdm 2.21
gnome gdm 2.22
gnome gdm 2.23
gnome gdm 2.24
gnome gdm 2.25
gnome gdm 2.26
gnome gdm 2.27
gnome gdm 2.28
gnome gdm 2.29
gnome gdm 2.30
gnome gdm 2.31
gnome gdm 2.32



{
  "configurations": [
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "3296F925-6D41-4DA7-BDB2-3B04CF22A53B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "7960EC63-69CF-474C-996C-E431CCDD07E9",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "A38317A3-3725-4F32-B675-00F8FB288F51",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "C4F01AD1-EB1B-4932-B8D7-CBC899B1A02E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "B760EB2A-6461-477F-B7E5-857117E21AE3",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "973BF2BF-BBF7-41F6-9E38-5150BC8AE7B6",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.8:*:*:*:*:*:*:*",
              "matchCriteriaId": "7756E66E-2296-4B20-ABC0-B1A2ACF2657B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.13:*:*:*:*:*:*:*",
              "matchCriteriaId": "BC30F499-35B6-40BB-A420-A55F6993DF3A",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.14:*:*:*:*:*:*:*",
              "matchCriteriaId": "70640B9F-4EAA-4513-80E4-9DD4A862F27D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.15:*:*:*:*:*:*:*",
              "matchCriteriaId": "27A6CC80-BC52-4B39-9424-E96DDA03666E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.16:*:*:*:*:*:*:*",
              "matchCriteriaId": "832DE81E-18BB-4276-A6B0-F316A322E83E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.17:*:*:*:*:*:*:*",
              "matchCriteriaId": "898A4607-107C-460F-8CF8-DEF63876B1C7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.18:*:*:*:*:*:*:*",
              "matchCriteriaId": "638AAAB0-2077-49F1-A909-0814C94EF96E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.19:*:*:*:*:*:*:*",
              "matchCriteriaId": "14C57E06-FBAB-4950-810D-ADDD74D271FE",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.20:*:*:*:*:*:*:*",
              "matchCriteriaId": "4AF56331-0008-4DFE-AB33-08399E48F499",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.21:*:*:*:*:*:*:*",
              "matchCriteriaId": "2DA4F51E-0ACE-4B31-BC58-027691C04941",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.22:*:*:*:*:*:*:*",
              "matchCriteriaId": "C37ED748-3C65-45B7-B59E-718A14295E7C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.23:*:*:*:*:*:*:*",
              "matchCriteriaId": "1EF1C68D-408A-4150-92C5-C2C392410282",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.24:*:*:*:*:*:*:*",
              "matchCriteriaId": "4A1C364D-5DDF-4B95-9545-AD3C6FD9C744",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.25:*:*:*:*:*:*:*",
              "matchCriteriaId": "0D6C0790-C762-48E4-A0BB-9FAD864AA913",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.26:*:*:*:*:*:*:*",
              "matchCriteriaId": "062D578B-AEF0-452C-A3AA-4A0D3F919F62",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.27:*:*:*:*:*:*:*",
              "matchCriteriaId": "52BDEFAD-DE2B-4E1E-B155-203E7CEFCFD6",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.28:*:*:*:*:*:*:*",
              "matchCriteriaId": "B9CD4961-40FC-4A01-A0D3-B904F479BAF2",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.29:*:*:*:*:*:*:*",
              "matchCriteriaId": "C0C3AC2D-F24A-4F0E-9433-1516BC61209A",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.30:*:*:*:*:*:*:*",
              "matchCriteriaId": "4EF547BB-BD34-4A38-B01A-E0059F70F7EA",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.31:*:*:*:*:*:*:*",
              "matchCriteriaId": "EAB2319A-2356-492A-A479-57F8D546E688",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:gnome:gdm:2.32:*:*:*:*:*:*:*",
              "matchCriteriaId": "59F0314A-4DA4-4767-8FC0-D372302E5F67",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ]
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "GNOME Display Manager (gdm) 2.x before 2.32.1 allows local users to change the ownership of arbitrary files via a symlink attack on a (1) dmrc or (2) face icon file under /var/cache/gdm/."
    },
    {
      "lang": "es",
      "value": "GNOME Display Manager (GDM) v2.x anterior a v2.32.1 permite a usuarios locales cambiar el propietario de archivos arbitrarios mediante un ataque de enlace simb\u00f3lico en un (1) DMRC o (2) fichero de icono en /var/cache/gdm/."
    }
  ],
  "id": "CVE-2011-0727",
  "lastModified": "2025-04-11T00:51:21.963",
  "metrics": {
    "cvssMetricV2": [
      {
        "acInsufInfo": false,
        "baseSeverity": "MEDIUM",
        "cvssData": {
          "accessComplexity": "MEDIUM",
          "accessVector": "LOCAL",
          "authentication": "NONE",
          "availabilityImpact": "COMPLETE",
          "baseScore": 6.9,
          "confidentialityImpact": "COMPLETE",
          "integrityImpact": "COMPLETE",
          "vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "version": "2.0"
        },
        "exploitabilityScore": 3.4,
        "impactScore": 10.0,
        "obtainAllPrivilege": false,
        "obtainOtherPrivilege": false,
        "obtainUserPrivilege": false,
        "source": "nvd@nist.gov",
        "type": "Primary",
        "userInteractionRequired": false
      }
    ]
  },
  "published": "2011-03-31T22:55:02.350",
  "references": [
    {
      "source": "security@ubuntu.com",
      "url": "http://ftp.gnome.org/pub/GNOME/sources/gdm/2.32/gdm-2.32.1.news"
    },
    {
      "source": "security@ubuntu.com",
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057333.html"
    },
    {
      "source": "security@ubuntu.com",
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057931.html"
    },
    {
      "source": "security@ubuntu.com",
      "tags": [
        "Patch"
      ],
      "url": "http://mail.gnome.org/archives/gdm-list/2011-March/msg00020.html"
    },
    {
      "source": "security@ubuntu.com",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://secunia.com/advisories/43714"
    },
    {
      "source": "security@ubuntu.com",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://secunia.com/advisories/43854"
    },
    {
      "source": "security@ubuntu.com",
      "url": "http://secunia.com/advisories/44021"
    },
    {
      "source": "security@ubuntu.com",
      "url": "http://securitytracker.com/id?1025264"
    },
    {
      "source": "security@ubuntu.com",
      "url": "http://www.debian.org/security/2011/dsa-2205"
    },
    {
      "source": "security@ubuntu.com",
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2011:070"
    },
    {
      "source": "security@ubuntu.com",
      "url": "http://www.redhat.com/support/errata/RHSA-2011-0395.html"
    },
    {
      "source": "security@ubuntu.com",
      "url": "http://www.securityfocus.com/bid/47063"
    },
    {
      "source": "security@ubuntu.com",
      "url": "http://www.ubuntu.com/usn/USN-1099-1"
    },
    {
      "source": "security@ubuntu.com",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://www.vupen.com/english/advisories/2011/0786"
    },
    {
      "source": "security@ubuntu.com",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://www.vupen.com/english/advisories/2011/0787"
    },
    {
      "source": "security@ubuntu.com",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://www.vupen.com/english/advisories/2011/0797"
    },
    {
      "source": "security@ubuntu.com",
      "url": "http://www.vupen.com/english/advisories/2011/0847"
    },
    {
      "source": "security@ubuntu.com",
      "url": "http://www.vupen.com/english/advisories/2011/0911"
    },
    {
      "source": "security@ubuntu.com",
      "tags": [
        "Patch"
      ],
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=688323"
    },
    {
      "source": "security@ubuntu.com",
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/66377"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://ftp.gnome.org/pub/GNOME/sources/gdm/2.32/gdm-2.32.1.news"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057333.html"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057931.html"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Patch"
      ],
      "url": "http://mail.gnome.org/archives/gdm-list/2011-March/msg00020.html"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://secunia.com/advisories/43714"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://secunia.com/advisories/43854"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://secunia.com/advisories/44021"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://securitytracker.com/id?1025264"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.debian.org/security/2011/dsa-2205"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2011:070"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.redhat.com/support/errata/RHSA-2011-0395.html"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.securityfocus.com/bid/47063"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.ubuntu.com/usn/USN-1099-1"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://www.vupen.com/english/advisories/2011/0786"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://www.vupen.com/english/advisories/2011/0787"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://www.vupen.com/english/advisories/2011/0797"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.vupen.com/english/advisories/2011/0847"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.vupen.com/english/advisories/2011/0911"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Patch"
      ],
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=688323"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/66377"
    }
  ],
  "sourceIdentifier": "security@ubuntu.com",
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-59"
        }
      ],
      "source": "nvd@nist.gov",
      "type": "Primary"
    }
  ]
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…