CVE-2011-1709
Title: Gnome Gdm Auth Bypass
Auth Bypass
Proof Of Concept
No public PoC currently indexed for CVE-2011-1709.
CWE Category
CWE-264
Published Date
Jun 14, 2011
Modified Date
Jun 16, 2026
Exploit Status
Not Found
Score
7.2
CVSS v2.0
Exploit Probability (EPSS)
0.43%
Vulnerability Summary
CVE-2011-1709: GNOME Display Manager (gdm) before 2.32.2, when glib 2.28 is used, enables execution of a web browser with the uid of the gdm account, which allows local users to gain privileges via vectors involving the x-scheme-handler/http MIME type.
Impacted Vendors
Reference Links
http://ftp.gnome.org/pub/GNOME/sources/gdm/2.32/gdm-2.32.2.news
http://git.gnome.org/browse/gdm/commit/?id=d13dd72531599ab7e4c747db3b58a8c17753e08d
http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061264.html
http://secunia.com/advisories/44797
http://secunia.com/advisories/44808
http://www.securityfocus.com/bid/48084
http://www.ubuntu.com/usn/USN-1142-1
https://bugzilla.redhat.com/show_bug.cgi?id=709139
https://hermes.opensuse.org/messages/8643655
http://ftp.gnome.org/pub/GNOME/sources/gdm/2.32/gdm-2.32.2.news
http://git.gnome.org/browse/gdm/commit/?id=d13dd72531599ab7e4c747db3b58a8c17753e08d
http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061264.html
http://secunia.com/advisories/44797
http://secunia.com/advisories/44808
http://www.securityfocus.com/bid/48084
http://www.ubuntu.com/usn/USN-1142-1
https://bugzilla.redhat.com/show_bug.cgi?id=709139
https://hermes.opensuse.org/messages/8643655
CVSS v2.0
Source Entity
[email protected]
Severity
HIGH
7.2
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:L/AC:L/Au:N/C:C/I:C/A:C
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2011-1709 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:L/AC:L/Au:N/C:C/I:C/A:C
Affected Stack
No specific products linked.