CVE-2018-14345
17.07.2018, 14:29
An issue was discovered in SDDM through 0.17.0. If configured with ReuseSession=true, the password is not checked for users with an already existing session. Any user with access to the system D-Bus can therefore unlock any graphical session. This is related to daemon/Display.cpp and helper/backend/PamBackend.cpp.Enginsight
Vendor | Product | Version |
---|---|---|
sddm_project | sddm | 𝑥 ≤ 0.17.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration