Advisories:rPSA-2006-0098
From rPath Wiki
rPath Security Advisory 2006-0098-1
Published: 2006-06-08
Products
- rPath Linux 1
Rating
- Severe
Exposure Level Classification
- Local System User Deterministic Privilege Escalation
Updated Versions
- gdm=conary.rpath.com@rpl:1/2.8.0.8-0.1-1
rPath Issue Tracking System
References
Description
- In previous versions of gdm, if the "face browser" feature is enabled
- (it is disabled by default), any user can access the gdm configuration
- screen with their own password instead of being required to provide the
- root password. This is known to enable subverting other user accounts,
- and may also enable subverting other system accounts, possibly including
- the root account. Disabling the "face browser" feature is an effective
- work-around for this vulnerability, but rPath recommends updating gdm
- to resolve it.
Copyright 2006 rPath, Inc. This file is distributed under the terms of the MIT License. A copy is available at http://www.rpath.com/permanent/mit-license.html
