Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Debian DSA-2205-1 Critical: gdm3 Privilege Escalation Risk

debian
Calendar Grey March 28, 2011
Debian Logo
Discover the latest gdm3 security patch for Debian addressing local privilege escalation issues. Prompt installation of these updates is crucial for system safety and integrity
Sebastian Krahmer discovered that the gdm3, the GNOME Desktop Manager, does not properly drop privileges when manipulating files related to the logged-in user

Summary

Sebastian Krahmer discovered that the gdm3, the GNOME Desktop Manager,
does not properly drop privileges when manipulating files related to
the logged-in user. As a result, local users can gain root
privileges.

The oldstable distribution (lenny) does not contain a gdm3 package.
The gdm package is not affected by this issue.

For the stable distribution (squeeze), this problem has been fixed in
version 2.30.5-6squeeze2.

For the testing distribution (wheezy) and the unstable distribution
(sid), this problem will be fixed soon.

We recommend that you upgrade your gdm3 packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: gdm3
CVE ID: CVE-2011-0727

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here