Bug 21717 - gdm new security issue CVE-2017-12164
Summary: gdm new security issue CVE-2017-12164
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA6-64-OK MGA6-32-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2017-09-16 05:03 CEST by David Walser
Modified: 2018-01-03 19:53 CET (History)
3 users (show)

See Also:
Source RPM: gdm-3.24.2-1.mga6.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2017-09-16 05:03:46 CEST
Fedora has issued an advisory today (September 15):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/CUDXKEMLQPVFJP52PBLEOLKUMYUY25UJ/

The issue is fixed upstream in 3.24.3.

Mageia 5 is not affected.
Marja Van Waes 2017-09-16 21:21:53 CEST

Assignee: bugsquad => gnome
CC: (none) => marja11

David Walser 2017-09-16 22:07:29 CEST

QA Contact: (none) => security
Component: RPM Packages => Security

Comment 1 David Walser 2018-01-01 19:34:29 CET
Advisory:
========================

Updated gdm packages fix security vulnerability:

A flaw was discovered in the gdm where gdm greeter was no longer setting the
ran_once boolean during autologin. If autologin was enable for a victim, an
attacker could simply select 'login as another user' to unlock their screen
(CVE-2017-12164).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12164
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/CUDXKEMLQPVFJP52PBLEOLKUMYUY25UJ/
========================

Updated packages in core/updates_testing:
========================
gdm-3.24.3-1.mga6
libgdm1-3.24.3-1.mga6
libgdm-gir1.0-3.24.3-1.mga6
libgdm-devel-3.24.3-1.mga6

from gdm-3.24.3-1.mga6.src.rpm

Assignee: gnome => qa-bugs

Comment 2 Thomas Backlund 2018-01-03 13:00:51 CET
Been running this for some days without issues

Whiteboard: (none) => MGA6-64-OK
CC: (none) => tmb

Comment 3 Thomas Backlund 2018-01-03 13:11:27 CET
advisory added to svn

Keywords: (none) => advisory

Comment 4 Thomas Backlund 2018-01-03 19:24:00 CET
Tested 32bit in virtualbox.

validating.

Whiteboard: MGA6-64-OK => MGA6-64-OK MGA6-32-OK
Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 5 Mageia Robot 2018-01-03 19:53:39 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2018-0056.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.