Lucene search

K
cveMitreCVE-2011-1709
HistoryJun 14, 2011 - 5:55 p.m.

CVE-2011-1709

2011-06-1417:55:03
CWE-264
mitre
web.nvd.nist.gov
36
cve-2011-1709
gdm
privilege escalation
mime type
local exploit
security vulnerability

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.3

Confidence

Low

EPSS

0

Percentile

5.1%

GNOME Display Manager (gdm) before 2.32.2, when glib 2.28 is used, enables execution of a web browser with the uid of the gdm account, which allows local users to gain privileges via vectors involving the x-scheme-handler/http MIME type.

Affected configurations

Nvd
Node
gnomegdmMatch1.0
OR
gnomegdmMatch2.0
OR
gnomegdmMatch2.2
OR
gnomegdmMatch2.3
OR
gnomegdmMatch2.4
OR
gnomegdmMatch2.5
OR
gnomegdmMatch2.6
OR
gnomegdmMatch2.8
OR
gnomegdmMatch2.13
OR
gnomegdmMatch2.14
OR
gnomegdmMatch2.15
OR
gnomegdmMatch2.16
OR
gnomegdmMatch2.17
OR
gnomegdmMatch2.18
OR
gnomegdmMatch2.19
OR
gnomegdmMatch2.20
OR
gnomegdmMatch2.21
OR
gnomegdmMatch2.22
OR
gnomegdmMatch2.23
OR
gnomegdmMatch2.24
OR
gnomegdmMatch2.25
OR
gnomegdmMatch2.26
OR
gnomegdmMatch2.27
OR
gnomegdmMatch2.28
OR
gnomegdmMatch2.29
OR
gnomegdmMatch2.30
OR
gnomegdmMatch2.31
OR
gnomegdmMatch2.32
OR
gnomegdmMatch2.32.1
AND
gnomeglibMatch2.28
VendorProductVersionCPE
gnomegdm1.0cpe:2.3:a:gnome:gdm:1.0:*:*:*:*:*:*:*
gnomegdm2.0cpe:2.3:a:gnome:gdm:2.0:*:*:*:*:*:*:*
gnomegdm2.2cpe:2.3:a:gnome:gdm:2.2:*:*:*:*:*:*:*
gnomegdm2.3cpe:2.3:a:gnome:gdm:2.3:*:*:*:*:*:*:*
gnomegdm2.4cpe:2.3:a:gnome:gdm:2.4:*:*:*:*:*:*:*
gnomegdm2.5cpe:2.3:a:gnome:gdm:2.5:*:*:*:*:*:*:*
gnomegdm2.6cpe:2.3:a:gnome:gdm:2.6:*:*:*:*:*:*:*
gnomegdm2.8cpe:2.3:a:gnome:gdm:2.8:*:*:*:*:*:*:*
gnomegdm2.13cpe:2.3:a:gnome:gdm:2.13:*:*:*:*:*:*:*
gnomegdm2.14cpe:2.3:a:gnome:gdm:2.14:*:*:*:*:*:*:*
Rows per page:
1-10 of 301

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.3

Confidence

Low

EPSS

0

Percentile

5.1%