Local File Ownership Change in GNOME Display Manager 2.x by Local Users
CVE-2011-0727
Currently unrated
Summary
The GNOME Display Manager (gdm) version 2.x prior to 2.32.1 is subject to a vulnerability that allows local users to execute a symlink attack. This can lead to unauthorized changes in file ownership of arbitrary files, specifically targeting the dmrc or face icon files located in the /var/cache/gdm/ directory. An attacker exploiting this vulnerability can gain control over sensitive files, posing significant security risks within the local environment.
References
Timeline
Vulnerability published
Vulnerability Reserved