First published: Tue Apr 25 2006(Updated: )
Race condition in daemon/slave.c in gdm before 2.14.1 allows local users to gain privileges via a symlink attack when gdm performs chown and chgrp operations on the .ICEauthority file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE GDM | =2.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1057 has been classified as a medium severity vulnerability due to its potential for privilege escalation.
CVE-2006-1057 is caused by a race condition in gdm when performing chown and chgrp operations on the .ICEauthority file.
To mitigate CVE-2006-1057, it is recommended to upgrade gdm to version 2.14.1 or later.
Local users of gdm versions prior to 2.14.1 are affected by CVE-2006-1057.
CVE-2006-1057 allows local users to gain elevated privileges via a symlink attack.