CVE-2006-2452
Summary
| CVE | CVE-2006-2452 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-06-09 10:02:00 UTC |
| Updated | 2018-10-03 21:40:00 UTC |
| Description | GNOME GDM 2.8, 2.12, 2.14, and 2.15, when the "face browser" feature is enabled, allows local users to access the "Configure Login Manager" functionality using their own password instead of the root password, which can be leveraged to gain additional privileges. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gnome | Gdm | 2.12 | All | All | All |
| Application | Gnome | Gdm | 2.14 | All | All | All |
| Application | Gnome | Gdm | 2.15 | All | All | All |
| Application | Gnome | Gdm | 2.8 | All | All | All |
| Application | Gnome | Gdm | 2.12 | All | All | All |
| Application | Gnome | Gdm | 2.14 | All | All | All |
| Application | Gnome | Gdm | 2.15 | All | All | All |
| Application | Gnome | Gdm | 2.8 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail | OVH- OVH | VUPEN | www.vupen.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| SUSE Updates for Multiple Packages - Advisories - Secunia | SECUNIA | secunia.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| USN-293-1: gdm vulnerability | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| SuSE Security announcements: [suse-security-announce] SUSE Security Summary Report SUSE-SR:2006:013 | SUSE | lists.suse.com | |
| GNOME Foundation GDM Configure Login Manager Authentication Bypass Vulnerability | BID | www.securityfocus.com | |
| GNOME Display Manager Configuration GUI Access Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | |
| Gentoo Linux Documentation -- GDM: Privilege escalation | GENTOO | www.gentoo.org | |
| Ubuntu update for gdm - Advisories - Secunia | SECUNIA | secunia.com | |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| Gentoo update for gdm - Advisories - Secunia | SECUNIA | secunia.com | |
| Bug 343476 – CRITICAL ERROR IN GDM! : GDM Allow to an ordinary user access to "Configure Login Manager..." | CONFIRM | bugzilla.gnome.org | |
| Mandriva update for gdm - Advisories - Secunia | SECUNIA | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.