Title : GNOME Display Manager Configure Login Manager Security Bypass Vulnerability VUPEN ID : VUPEN/ADV-2006-2239 CVE ID : CVE-2006-2452
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-06-09
Technical Description
A vulnerability has been identified in GNOME Display Manager (GDM), which could be exploited by malicious users to bypass security restrictions and gain elevated privileges. This flaw is due to an error in the "Face Browser" feature that allows local users to access the "Configure Login Manager" functionality using their own password instead of the root password, which could be exploited by local attackers to potentially obtain elevated privileges.