Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vj28-g7j2-2wxf

Опубликовано: 02 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validation of session agents using D-Bus methods related to transitioning a client connection from the login screen to the user session. As a result, the system RDP TLS certificate and key can be exposed to unauthorized users. This flaw allows a malicious user on the system to take control of the RDP client connection during the login screen-to-user session transition.

A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validation of session agents using D-Bus methods related to transitioning a client connection from the login screen to the user session. As a result, the system RDP TLS certificate and key can be exposed to unauthorized users. This flaw allows a malicious user on the system to take control of the RDP client connection during the login screen-to-user session transition.

EPSS

Процентиль: 42%
0.002
Низкий

7.5 High

CVSS3

Дефекты

CWE-488

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validation of session agents using D-Bus methods related to transitioning a client connection from the login screen to the user session. As a result, the system RDP TLS certificate and key can be exposed to unauthorized users. This flaw allows a malicious user on the system to take control of the RDP client connection during the login screen-to-user session transition.

CVSS3: 7.5
redhat
больше 1 года назад

A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validation of session agents using D-Bus methods related to transitioning a client connection from the login screen to the user session. As a result, the system RDP TLS certificate and key can be exposed to unauthorized users. This flaw allows a malicious user on the system to take control of the RDP client connection during the login screen-to-user session transition.

CVSS3: 7.5
nvd
больше 1 года назад

A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validation of session agents using D-Bus methods related to transitioning a client connection from the login screen to the user session. As a result, the system RDP TLS certificate and key can be exposed to unauthorized users. This flaw allows a malicious user on the system to take control of the RDP client connection during the login screen-to-user session transition.

CVSS3: 7.5
debian
больше 1 года назад

A flaw was found in the gnome-remote-desktop package. The gnome-remote ...

CVSS3: 7.5
fstec
больше 1 года назад

Уязвимость пакета для удаленного подключения к компьютеру GNOME Remote Desktop, связанная с предоставлением элемента данных для ошибочного сеанса, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 42%
0.002
Низкий

7.5 High

CVSS3

Дефекты

CWE-488