CVE Vulnerabilities

CVE-2011-1709

Published: Jun 14, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
4 MODERATE
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

GNOME Display Manager (gdm) before 2.32.2, when glib 2.28 is used, enables execution of a web browser with the uid of the gdm account, which allows local users to gain privileges via vectors involving the x-scheme-handler/http MIME type.

Affected Software

NameVendorStart VersionEnd Version
GdmGnome1.0 (including)1.0 (including)
GdmGnome2.0 (including)2.0 (including)
GdmGnome2.2 (including)2.2 (including)
GdmGnome2.3 (including)2.3 (including)
GdmGnome2.4 (including)2.4 (including)
GdmGnome2.5 (including)2.5 (including)
GdmGnome2.6 (including)2.6 (including)
GdmGnome2.8 (including)2.8 (including)
GdmGnome2.13 (including)2.13 (including)
GdmGnome2.14 (including)2.14 (including)
GdmGnome2.15 (including)2.15 (including)
GdmGnome2.16 (including)2.16 (including)
GdmGnome2.17 (including)2.17 (including)
GdmGnome2.18 (including)2.18 (including)
GdmGnome2.19 (including)2.19 (including)
GdmGnome2.20 (including)2.20 (including)
GdmGnome2.21 (including)2.21 (including)
GdmGnome2.22 (including)2.22 (including)
GdmGnome2.23 (including)2.23 (including)
GdmGnome2.24 (including)2.24 (including)
GdmGnome2.25 (including)2.25 (including)
GdmGnome2.26 (including)2.26 (including)
GdmGnome2.27 (including)2.27 (including)
GdmGnome2.28 (including)2.28 (including)
GdmGnome2.29 (including)2.29 (including)
GdmGnome2.30 (including)2.30 (including)
GdmGnome2.31 (including)2.31 (including)
GdmGnome2.32 (including)2.32 (including)
GdmGnome2.32.1 (including)2.32.1 (including)
GdmUbuntudevel*
GdmUbuntuhardy*
GdmUbuntunatty*

References