Permissions, Privileges, and Access Controls in Fedora - CVE-2015-7496

 

Permissions, Privileges, and Access Controls in Fedora - CVE-2015-7496

Published: November 24, 2015 / Updated: August 9, 2020


Vulnerability identifier: #VU40591
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-7496
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

GNOME Display Manager (gdm) before 3.18.2 allows physically proximate attackers to bypass the lock screen by holding the Escape key.


Affected software

Fedora
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server for ARM
gdm
gnome-session (Red Hat package)
gdm (Red Hat package)

How to mitigate CVE-2015-7496

Install update from vendor's website.

gdm - update to 3.18.2-1.fc23
gnome-session (Red Hat package) - update to 3.22.3-4.el7
gdm (Red Hat package) - update to 3.22.3-11.el7

External References

Related Security Bulletins