SB2015112407 - Permissions, Privileges, and Access Controls in Fedoraproject Fedora
Published: November 24, 2015 Updated: August 9, 2020
Security Bulletin ID
SB2015112407
Severity
High
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2015-7496)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
GNOME Display Manager (gdm) before 3.18.2 allows physically proximate attackers to bypass the lock screen by holding the Escape key.
Remediation
Install update from vendor's website.
References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172328.html
- http://www.openwall.com/lists/oss-security/2015/11/17/10
- http://www.openwall.com/lists/oss-security/2015/11/17/8
- https://access.redhat.com/errata/RHSA-2017:2128
- https://bugzilla.gnome.org/show_bug.cgi?id=758032
- https://download.gnome.org/sources/gdm/3.18/gdm-3.18.2.news