Mageia 2021-0003: gdm security update
Summary
Kevin Backhouse discovered that GDM incorrectly launched the initial setup tool
when the accountsservice daemon was not reachable. A local attacker able to
cause accountsservice to crash or stop responding could trick GDM into
launching the initial setup tool and create a privileged user (CVE-2020-16125).
References
- https://bugs.mageia.org/show_bug.cgi?id=27566
- https://ubuntu.com/security/notices/USN-4614-1
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZX3UTGQD6BVLNXN2RQDQJAGIEKRWA7A4/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16125
Resolution
MGASA-2021-0003 - Updated gdm packages fix a security vulnerability
SRPMS
- 7/core/gdm-3.32.0-1.1.mga7