GNOME Display Manager (gdm) before 2.21.1 allows local users to change permissions of arbitrary directories via a symlink attack on /tmp/.X11-unix/.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Link | Tags |
---|---|
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=988498 | patch |
http://secunia.com/advisories/54661 | third party advisory vendor advisory |
http://rhn.redhat.com/errata/RHSA-2013-1213.html | vendor advisory |