Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-16125

Опубликовано: 10 нояб. 2020
Источник: redhat
CVSS3: 6.4

Описание

gdm3 versions before 3.36.2 or 3.38.2 would start gnome-initial-setup if gdm3 can't contact the accountservice service via dbus in a timely manner; on Ubuntu (and potentially derivatives) this could be be chained with an additional issue that could allow a local user to create a new privileged account.

A vulnerability was found in GDM. If gdm can't contact the AccountService service via DBus in a timely manner it would default to assume there are no existing users and would allow the attacker to create a new user with high privileges.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gdmOut of support scope
Red Hat Enterprise Linux 6gdmOut of support scope
Red Hat Enterprise Linux 7gdmOut of support scope
Red Hat Enterprise Linux 9gdmNot affected
Red Hat Enterprise Linux 8gdmFixedRHSA-2021:158618.05.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-636
https://bugzilla.redhat.com/show_bug.cgi?id=1901994gdm: inability to timely contact accountservice via dbus leads gnome-initial-setup to creation of account with admin privileges

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.2
ubuntu
больше 4 лет назад

gdm3 versions before 3.36.2 or 3.38.2 would start gnome-initial-setup if gdm3 can't contact the accountservice service via dbus in a timely manner; on Ubuntu (and potentially derivatives) this could be be chained with an additional issue that could allow a local user to create a new privileged account.

CVSS3: 7.2
nvd
больше 4 лет назад

gdm3 versions before 3.36.2 or 3.38.2 would start gnome-initial-setup if gdm3 can't contact the accountservice service via dbus in a timely manner; on Ubuntu (and potentially derivatives) this could be be chained with an additional issue that could allow a local user to create a new privileged account.

CVSS3: 7.2
debian
больше 4 лет назад

gdm3 versions before 3.36.2 or 3.38.2 would start gnome-initial-setup ...

suse-cvrf
больше 4 лет назад

Security update for gdm

suse-cvrf
больше 4 лет назад

Security update for gdm

6.4 Medium

CVSS3