CVE-2017-12164
26.07.2018, 16:29
A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin. If autologin was enabled for a victim, an attacker could simply select 'login as another user' to unlock their screen.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gnome | gnome_display_manager | 3.24.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| gdm |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| gdm-devel |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| gdm-lang |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| gdm-schema |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| gdm-systemd |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| gdmflexiserver |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| libgdm1 |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| typelib-1_0-Gdm-1_0 |
|
Common Weakness Enumeration
- CWE-592 - DEPRECATED: Authentication Bypass IssuesThis weakness has been deprecated because it covered redundant concepts already described in CWE-287.
- CWE-665 - Improper InitializationThe software does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.