Vulnerability Name:

CVE-2006-1057 (CCN-26092)

Assigned:2006-04-19
Published:2006-04-19
Updated:2018-10-03
Summary:Race condition in daemon/slave.c in gdm before 2.14.1 allows local users to gain privileges via a symlink attack when gdm performs chown and chgrp operations on the .ICEauthority file.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:3.7 Low (CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
2.6 Low (CCN CVSS v2 Vector: AV:L/AC:H/Au:N/C:N/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-362
Vulnerability Consequences:File Manipulation
References:Source: MITRE
Type: CNA
CVE-2006-1057

Source: CONFIRM
Type: UNKNOWN
http://cvs.gnome.org/viewcvs/gdm2/daemon/slave.c?r1=1.260&r2=1.261

Source: CCN
Type: RHSA-2007-0286
Low: gdm security and bug fix update

Source: CCN
Type: ASA-2007-202
gdm security and bug fix update (RHSA-2007-0286)

Source: DEBIAN
Type: Patch, Vendor Advisory
DSA-1040

Source: DEBIAN
Type: DSA-1040
gdm -- programming error

Source: CCN
Type: GDM Web site
GDM: the GNOME DISPLAY MANAGER

Source: MANDRIVA
Type: UNKNOWN
MDKSA-2006:083

Source: REDHAT
Type: UNKNOWN
RHSA-2007:0286

Source: BID
Type: UNKNOWN
17635

Source: CCN
Type: BID-17635
GNOME Foundation GDM .ICEauthority Improper File Permissions Vulnerability

Source: CCN
Type: USN-278-1
gdm vulnerability

Source: VUPEN
Type: Vendor Advisory
ADV-2006-1465

Source: CONFIRM
Type: UNKNOWN
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=188303

Source: XF
Type: UNKNOWN
gdm-slavec-symlink(26092)

Source: XF
Type: UNKNOWN
gdm-slavec-symlink(26092)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:10092

Source: UBUNTU
Type: UNKNOWN
USN-278-1

Source: FEDORA
Type: Patch
FEDORA-2006-338

Vulnerable Configuration:Configuration 1:
  • cpe:/a:gnome:gdm:2.14:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:4:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:10092
    V
    Race condition in daemon/slave.c in gdm before 2.14.1 allows local users to gain privileges via a symlink attack when gdm performs chown and chgrp operations on the .ICEauthority file.
    2013-04-29
    oval:com.redhat.rhsa:def:20070286
    P
    RHSA-2007:0286: gdm security and bug fix update (Low)
    2007-05-01
    oval:org.debian:def:1040
    V
    programming error
    2006-04-24
    BACK
    gnome gdm 2.14