CVE-2011-1946

gnomesu-pam-backend in libgnomesu 1.0.0 prints an error message but proceeds with the non-error code path upon failure of the setgid or setuid function, which allows local users to gain privileges by leveraging access to two unprivileged user accounts, and running many processes under one of these accounts.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 14%
Affected Products (NVD)
VendorProductVersion
hongli_lailibgnomesu
1.0.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libgnomesu
hardy
ignored
lucid
dne
maverick
dne
natty
dne
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libgnomesu
suse enterprise sap 12 SP5
2.0.0-353.6.2
fixed
suse enterprise server 12
1.0.0-352.84
fixed
suse enterprise server 12 SP1
1.0.0-352.84
fixed
suse enterprise server 12 SP2
2.0.0-353.6.2
fixed
suse enterprise server 12 SP3
2.0.0-353.6.2
fixed
suse enterprise server 12 SP4
2.0.0-353.6.2
fixed
suse enterprise server 12 SP5
2.0.0-353.6.2
fixed
libgnomesu-lang
suse enterprise sap 12 SP5
2.0.0-353.6.2
fixed
suse enterprise server 12
1.0.0-352.84
fixed
suse enterprise server 12 SP1
1.0.0-352.84
fixed
suse enterprise server 12 SP2
2.0.0-353.6.2
fixed
suse enterprise server 12 SP3
2.0.0-353.6.2
fixed
suse enterprise server 12 SP4
2.0.0-353.6.2
fixed
suse enterprise server 12 SP5
2.0.0-353.6.2
fixed
libgnomesu0
suse enterprise sap 12 SP5
2.0.0-353.6.2
fixed
suse enterprise server 12
1.0.0-352.84
fixed
suse enterprise server 12 SP1
1.0.0-352.84
fixed
suse enterprise server 12 SP2
2.0.0-353.6.2
fixed
suse enterprise server 12 SP3
2.0.0-353.6.2
fixed
suse enterprise server 12 SP4
2.0.0-353.6.2
fixed
suse enterprise server 12 SP5
2.0.0-353.6.2
fixed
Common Weakness Enumeration