MEDIUM
Format string vulnerability in the host chooser window (gdmchooser) in GNOME Foundation Display Manager (gdm) allows local users to execute arbitrary code via format string specifiers in a hostname, which are used in an error dialog
Published Dec 15, 2006
4.3
MEDIUMCVSS 2.0
EPSS 0.41%
Description
Format string vulnerability in the host chooser window (gdmchooser) in GNOME Foundation Display Manager (gdm) allows local users to execute arbitrary code via format string specifiers in a hostname, which are used in an error dialog.
Affected products
Remediation
Red Hat statement
Not vulnerable. This flaw was first introduced in gdm version 2.14. Therefore these issues did not affect the earlier versions of gdm as shipped with Red Hat Enterprise Linux 2.1, 3, or 4. Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Weaknesses (0)
No CWE recorded.
References (19)
- http://ftp.acc.umu.se/pub/GNOME/sources/gdm/2.17/gdm-2.17.4.news x_refsource_CONFIRM
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=453 third-party-advisoryx_refsource_IDEFENSEVendor Advisory
- http://secunia.com/advisories/23381 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23385 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23387 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23409 third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1017320 vdb-entryx_refsource_SECTRACKPatch
- http://securitytracker.com/id?1017383 vdb-entryx_refsource_SECTRACK
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:231 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2006_29_sr.html vendor-advisoryx_refsource_SUSE
- http://www.osvdb.org/30848 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/bid/21597 vdb-entryx_refsource_BIDPatch
- http://www.ubuntu.com/usn/usn-396-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2006/5015 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2006-6105 Vendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-6088 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30896 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2006-6105
- https://www.cve.org/CVERecord?id=CVE-2006-6105
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 15, 2006
Updated Aug 7, 2024
Reserved Nov 24, 2006
Link CVE-2006-6105
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data