Lucene search

K
cve[email protected]CVE-2006-2452
HistoryJun 09, 2006 - 10:02 a.m.

CVE-2006-2452

2006-06-0910:02:00
web.nvd.nist.gov
23
gnome
gdm
face browser
local users
additional privileges
cve-2006-2452
nvd

3.7 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:H/Au:N/C:P/I:P/A:P

6.4 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

12.7%

GNOME GDM 2.8, 2.12, 2.14, and 2.15, when the “face browser” feature is enabled, allows local users to access the “Configure Login Manager” functionality using their own password instead of the root password, which can be leveraged to gain additional privileges.

Affected configurations

NVD
Node
gnomegdmMatch2.8
OR
gnomegdmMatch2.12
OR
gnomegdmMatch2.14
OR
gnomegdmMatch2.15

3.7 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:H/Au:N/C:P/I:P/A:P

6.4 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

12.7%