CVE-2006-1057: Race Condition
Published Apr 25, 2006
·Updated
Race condition in daemon/slave.c in gdm before 2.14.1 allows local users to gain privileges via a symlink attack when gdm performs chown and chgrp operations on the .ICEauthority file.
Affected Software
1 affected component
Gnome gdm=2.14
Remediation
Patch Available
Event History
Apr 25, 2006
CVE Published
01:02 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1057?
CVE-2006-1057 has been classified as a medium severity vulnerability due to its potential for privilege escalation.
2
What causes the vulnerability identified in CVE-2006-1057?
CVE-2006-1057 is caused by a race condition in gdm when performing chown and chgrp operations on the .ICEauthority file.
3
How do I fix CVE-2006-1057?
To mitigate CVE-2006-1057, it is recommended to upgrade gdm to version 2.14.1 or later.
4
Who is affected by CVE-2006-1057?
Local users of gdm versions prior to 2.14.1 are affected by CVE-2006-1057.
5
What types of attacks can be executed due to CVE-2006-1057?
CVE-2006-1057 allows local users to gain elevated privileges via a symlink attack.