GDM: Privilege escalation An authentication error in GDM could allow users to gain elevated privileges. gdm 2006-06-12 2006-06-19 135027 local 2.8.0.8 2.8.0.8

GDM is the GNOME display manager.

GDM allows a normal user to access the configuration manager.

When the "face browser" in GDM is enabled, a normal user can use the "configure login manager" with his/her own password instead of the root password, and thus gain additional privileges.

There is no known workaround at this time.

All GDM users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=gnome-base/gdm-2.8.0.8"
Gnome Bugzilla entry CVE-2006-2452 falco daxomatic jaervosz