Red Hat GNOME Display Manager Security Bypass Vulnerability
BID:36219
Info
Red Hat GNOME Display Manager Security Bypass Vulnerability
| Bugtraq ID: | 36219 |
| Class: | Design Error |
| CVE: |
CVE-2009-2697 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 02 2009 12:00AM |
| Updated: | Oct 16 2009 08:38PM |
| Credit: | Red Hat |
| Vulnerable: |
Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 server Avaya Aura Session Manager 1.1 |
| Not Vulnerable: | |
Discussion
Red Hat GNOME Display Manager Security Bypass Vulnerability
The Red Hat GNOME Display Manager package is prone to a vulnerability that may create a false sense of security. Specifically, the issue may cause an administrator to incorrectly assume that access restrictions are in place.
Attackers can exploit this issue to gain unauthorized access to privileged resources.
This issue affects Red Hat Enterprise Linux Desktop (v. 5 client) and Red Hat Enterprise Linux (v. 5 server).
The Red Hat GNOME Display Manager package is prone to a vulnerability that may create a false sense of security. Specifically, the issue may cause an administrator to incorrectly assume that access restrictions are in place.
Attackers can exploit this issue to gain unauthorized access to privileged resources.
This issue affects Red Hat Enterprise Linux Desktop (v. 5 client) and Red Hat Enterprise Linux (v. 5 server).
Exploit / POC
Red Hat GNOME Display Manager Security Bypass Vulnerability
An attacker may carry out attacks using standard tools and utilities.
An attacker may carry out attacks using standard tools and utilities.
Solution / Fix
Red Hat GNOME Display Manager Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Red Hat GNOME Display Manager Security Bypass Vulnerability
References:
References: