Skip to navigation

Bug Fix Advisory gdm bug fix update

Advisory: RHBA-2005:151-13
Type: Bug Fix Advisory
Severity: N/A
Issued on: 2005-06-09
Last updated on: 2005-06-09
Affected Products: Red Hat Desktop (v. 4)
Red Hat Enterprise Linux AS (v. 4)
Red Hat Enterprise Linux ES (v. 4)
Red Hat Enterprise Linux WS (v. 4)

Details

An updated gdm package that fixes various issues is now available.

The GNOME Display Manager, gdm, is a highly configurable
re-implementation of xdm, the X Display Manager. It allows users to log
into systems with the X Window System running and supports running
several different X sessions on a local machine at the same time.

This updated gdm package addresses the following issues:

- gdm erroneously used the source IP instead of the connection address
of XDMCP request packets. This would cause problems using XDMCP through
NAT firewalls.

- gdm did not determine the canonical username before logging in. This
would cause problems logging in with PAM and NSS setups that allow more
than one username per user.

- gdm tried to test for the existance of a user's home directory as root
instead of as the user being logged in, so an error would be generated in
configurations where root didn't have access to the user's home directory.

All users of gdm should upgrade to this updated package, which resolves
these issues.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat
Network to download and update your packages. To launch the Red Hat
Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the
following Web page for the System Administration or Customization
guide specific to your system:

http://www.redhat.com/docs/manuals/enterprise/

Updated packages

Red Hat Desktop (v. 4)

SRPMS:
gdm-2.6.0.5-7.rhel4.1.src.rpm
File outdated by:  RHSA-2010:0657
    MD5: c37f824994e90b0e9d74a7fd4b52c51a
 
IA-32:
gdm-2.6.0.5-7.rhel4.1.i386.rpm
File outdated by:  RHSA-2010:0657
    MD5: 1c0d426602ac16a4aeb48bd01fe1d19a
 
x86_64:
gdm-2.6.0.5-7.rhel4.1.x86_64.rpm
File outdated by:  RHSA-2010:0657
    MD5: c20812294cba4dc0856200beeabb24b2
 
Red Hat Enterprise Linux AS (v. 4)

SRPMS:
gdm-2.6.0.5-7.rhel4.1.src.rpm
File outdated by:  RHSA-2010:0657
    MD5: c37f824994e90b0e9d74a7fd4b52c51a
 
IA-32:
gdm-2.6.0.5-7.rhel4.1.i386.rpm
File outdated by:  RHSA-2010:0657
    MD5: 1c0d426602ac16a4aeb48bd01fe1d19a
 
IA-64:
gdm-2.6.0.5-7.rhel4.1.ia64.rpm
File outdated by:  RHSA-2010:0657
    MD5: b2bfc18f156c0b317ed39a811c94a37e
 
PPC:
gdm-2.6.0.5-7.rhel4.1.ppc.rpm
File outdated by:  RHSA-2010:0657
    MD5: 4447a8d358efd1102b1e86c93a3667b7
 
s390:
gdm-2.6.0.5-7.rhel4.1.s390.rpm
File outdated by:  RHSA-2010:0657
    MD5: 2e82d4b2058f3f97b719c834bbaee03c
 
s390x:
gdm-2.6.0.5-7.rhel4.1.s390x.rpm
File outdated by:  RHSA-2010:0657
    MD5: b8d03efd4d67c475926f12c835d6694d
 
x86_64:
gdm-2.6.0.5-7.rhel4.1.x86_64.rpm
File outdated by:  RHSA-2010:0657
    MD5: c20812294cba4dc0856200beeabb24b2
 
Red Hat Enterprise Linux ES (v. 4)

SRPMS:
gdm-2.6.0.5-7.rhel4.1.src.rpm
File outdated by:  RHSA-2010:0657
    MD5: c37f824994e90b0e9d74a7fd4b52c51a
 
IA-32:
gdm-2.6.0.5-7.rhel4.1.i386.rpm
File outdated by:  RHSA-2010:0657
    MD5: 1c0d426602ac16a4aeb48bd01fe1d19a
 
IA-64:
gdm-2.6.0.5-7.rhel4.1.ia64.rpm
File outdated by:  RHSA-2010:0657
    MD5: b2bfc18f156c0b317ed39a811c94a37e
 
x86_64:
gdm-2.6.0.5-7.rhel4.1.x86_64.rpm
File outdated by:  RHSA-2010:0657
    MD5: c20812294cba4dc0856200beeabb24b2
 
Red Hat Enterprise Linux WS (v. 4)

SRPMS:
gdm-2.6.0.5-7.rhel4.1.src.rpm
File outdated by:  RHSA-2010:0657
    MD5: c37f824994e90b0e9d74a7fd4b52c51a
 
IA-32:
gdm-2.6.0.5-7.rhel4.1.i386.rpm
File outdated by:  RHSA-2010:0657
    MD5: 1c0d426602ac16a4aeb48bd01fe1d19a
 
IA-64:
gdm-2.6.0.5-7.rhel4.1.ia64.rpm
File outdated by:  RHSA-2010:0657
    MD5: b2bfc18f156c0b317ed39a811c94a37e
 
x86_64:
gdm-2.6.0.5-7.rhel4.1.x86_64.rpm
File outdated by:  RHSA-2010:0657
    MD5: c20812294cba4dc0856200beeabb24b2
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

149899 - gdm should call setegid and seteuid before calling g_file_test on the user's home directory



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/