CVE-2011-1946
Summary
| CVE | CVE-2011-1946 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-07-07 21:55:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | gnomesu-pam-backend in libgnomesu 1.0.0 prints an error message but proceeds with the non-error code path upon failure of the setgid or setuid function, which allows local users to gain privileges by leveraging access to two unprivileged user accounts, and running many processes under one of these accounts. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hongli Lai | Libgnomesu | 1.0.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - Re: CVE request: libgnomesu privilege escalation | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Patch |
| oss-security - CVE request: libgnomesu privilege escalation | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Patch |
| libgnomesu PAM Backend 'setuid()' Return Value Local Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Bug 695627 – VUL-0: libgnomesu pam backend missing setuid() retval check | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.novell.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.