Lucene search

K
ubuntuUbuntuUSN-278-1
HistoryMay 04, 2006 - 12:00 a.m.

gdm vulnerability

2006-05-0400:00:00
ubuntu.com
35

3.7 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:H/Au:N/C:P/I:P/A:P

6.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.6%

Releases

  • Ubuntu 5.10
  • Ubuntu 5.04

Details

Marcus Meissner discovered a race condition in gdm’s handling of the
~/.ICEauthority file permissions. A local attacker could exploit this
to become the owner of an arbitrary file in the system. When getting
control over automatically executed scripts (like cron jobs), the
attacker could eventually leverage this flaw to execute arbitrary
commands with root privileges.

OSVersionArchitecturePackageVersionFilename
Ubuntu5.10noarchgdm< *UNKNOWN
Ubuntu5.04noarchgdm< *UNKNOWN

3.7 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:H/Au:N/C:P/I:P/A:P

6.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.6%