CVE-2020-16125 log
| Source |
|
| Severity | High |
| Remote | No |
| Type | Privilege escalation |
| Description | gdm before 3.38.2 can be tricked into launching gnome-initial-setup, enabling an unprivileged user to create a new user account for themselves. The new account is a member of the sudo group, so this enables the unprivileged user to obtain admin privileges. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-1264 | gdm | 3.38.1-3 | 3.38.2-1 | High | Fixed |
| Date | Advisory | Group | Package | Severity | Type |
|---|---|---|---|---|---|
| 10 Nov 2020 | ASA-202011-5 | AVG-1264 | gdm | High | privilege escalation |
| References |
|---|
https://gitlab.gnome.org/GNOME/gdm/-/issues/642 |