Kevin Backhouse discovered that GDM incorrectly launched the initial setup tool
when the accountsservice daemon was not reachable. A local attacker able to
cause accountsservice to crash or stop responding could trick GDM into
launching the initial setup tool and create a privileged user (CVE-2020-16125).
- https://bugs.mageia.org/show_bug.cgi?id=27566
- https://ubuntu.com/security/notices/USN-4614-1
-
- https://www.cve.org/CVERecord?id=CVE-2020-16125
- 7/core/gdm-3.32.0-1.1.mga7
Get the latest Linux and open source security news straight to your inbox.