Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-12164

Опубликовано: 26 июл. 2018
Источник: nvd
CVSS3: 4.1
CVSS3: 6.4
CVSS2: 6.9
EPSS Низкий

Описание

A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin. If autologin was enabled for a victim, an attacker could simply select 'login as another user' to unlock their screen.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gnome:gnome_display_manager:3.24.1:*:*:*:*:*:*:*

EPSS

Процентиль: 31%
0.00117
Низкий

4.1 Medium

CVSS3

6.4 Medium

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-592
CWE-665

Связанные уязвимости

CVSS3: 4.1
ubuntu
больше 7 лет назад

A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin. If autologin was enabled for a victim, an attacker could simply select 'login as another user' to unlock their screen.

CVSS3: 4.1
redhat
больше 8 лет назад

A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin. If autologin was enabled for a victim, an attacker could simply select 'login as another user' to unlock their screen.

CVSS3: 4.1
debian
больше 7 лет назад

A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer se ...

CVSS3: 6.4
github
больше 3 лет назад

A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin. If autologin was enabled for a victim, an attacker could simply select 'login as another user' to unlock their screen.

EPSS

Процентиль: 31%
0.00117
Низкий

4.1 Medium

CVSS3

6.4 Medium

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-592
CWE-665