Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2006:083: gdm Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the gdm package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2006:083 (gdm).
A race condition in daemon/slave.c in gdm before 2.14.1 allows local
users to gain rights via a symlink attack when gdm performs chown
and chgrp operations on the .ICEauthority file.
Packages have been patched to correct this issue.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:083
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.