CVE-2013-4169: Medium severity gnome display manager vulnerability
Published Sep 10, 2013
·Updated
GNOME Display Manager (gdm) before 2.21.1 allows local users to change permissions of arbitrary directories via a symlink attack on /tmp/.X11-unix/.
Affected Software
44 affected components
Gnome GNOME Display Manager<=2.21
Gnome GNOME Display Manager=0.7
Gnome GNOME Display Manager=1.0
Gnome GNOME Display Manager=2.0
Gnome GNOME Display Manager=2.2
Gnome GNOME Display Manager=2.13
Gnome GNOME Display Manager=2.14
Gnome GNOME Display Manager=2.14.1
Gnome GNOME Display Manager=2.14.2
Gnome GNOME Display Manager=2.14.3
Gnome GNOME Display Manager=2.14.4
Gnome GNOME Display Manager=2.14.5
Gnome GNOME Display Manager=2.14.6
Gnome GNOME Display Manager=2.14.7
Gnome GNOME Display Manager=2.14.8
Gnome GNOME Display Manager=2.14.9
Gnome GNOME Display Manager=2.14.10
Gnome GNOME Display Manager=2.14.11
Gnome GNOME Display Manager=2.14.12
Gnome GNOME Display Manager=2.15
Gnome GNOME Display Manager=2.16
Gnome GNOME Display Manager=2.16.1
Gnome GNOME Display Manager=2.16.2
Gnome GNOME Display Manager=2.17
Gnome GNOME Display Manager=2.18
Gnome GNOME Display Manager=2.18.1
Gnome GNOME Display Manager=2.18.2
Gnome GNOME Display Manager=2.18.3
Gnome GNOME Display Manager=2.19
Gnome GNOME Display Manager=2.19.1
Gnome GNOME Display Manager=2.19.2
Gnome GNOME Display Manager=2.19.3
Gnome GNOME Display Manager=2.19.4
Gnome GNOME Display Manager=2.20.0
Gnome GNOME Display Manager=2.20.1
Gnome GNOME Display Manager=2.20.2
Gnome GNOME Display Manager=2.20.3
Gnome GNOME Display Manager=2.20.4
Gnome GNOME Display Manager=2.20.5
Gnome GNOME Display Manager=2.20.6
Gnome GNOME Display Manager=2.20.7
Gnome GNOME Display Manager=2.20.8
Gnome GNOME Display Manager=2.20.9
Gnome GNOME Display Manager=2.20.10
Remediation
Patch Available
Event History
Sep 10, 2013
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4169?
CVE-2013-4169 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2013-4169?
To fix CVE-2013-4169, upgrade to GNOME Display Manager version 2.21.1 or later.
3
Who is affected by CVE-2013-4169?
CVE-2013-4169 affects local users of GNOME Display Manager versions prior to 2.21.1.
4
What type of attack does CVE-2013-4169 involve?
CVE-2013-4169 involves a symlink attack that allows local users to change permissions of arbitrary directories.
5
What software does CVE-2013-4169 impact?
CVE-2013-4169 impacts various versions of GNOME Display Manager up to 2.21.