|
GNOME Display Manager Multiple Vulnerabilities
|
|
Secunia Advisory:
|
SA9571
|
|
|
Release Date:
|
2003-08-22
|
|
Popularity:
|
9,016 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
Exposure of sensitive information DoS
|
|
Where:
|
From local network
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | GNOME Display Manager (GDM) 2.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2003-0547 CVE-2003-0548 CVE-2003-0549
|
|
Description: Three vulnerabilities have been reported in GNOME Display Manager (GDM), which can be exploited by malicious users to read arbitrary files on the system or cause a Denial of Service (DoS).
The first vulnerability is caused due to an error in the "examine session errors" feature. The problem is that GDM reads the "~/.xsession-errors" file with "root" privileges, which can be exploited to disclose the content of arbitrary files on the system via a symlink attack.
Successful exploitation requires that the session lasts less than 10 seconds.
The two other vulnerabilities are caused due to errors in the X Display Manager Control Protocol (XDMCP), which can be exploited by malicious people to crash the gdm daemon.
Solution: The vulnerabilities have been fixed in version 2.4.2.100 and later.
http://ftp.gnome.org/pub/GNOME/sources/gdm/2.4/
Original Advisory: http://cvs.gnome.org/lxr/source/gdm2/NEWS#83
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|