Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-14424

Опубликовано: 14 авг. 2018
Источник: nvd
CVSS3: 7.8
CVSS2: 4.6
EPSS Низкий

Описание

The daemon in GDM through 3.29.1 does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local attacker to trigger a use-after-free via a specially crafted sequence of D-Bus method calls, resulting in a denial of service or potential code execution.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gnome:gnome_display_manager:*:*:*:*:*:*:*:*
Версия до 3.29.1 (включая)

EPSS

Процентиль: 22%
0.00074
Низкий

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 7 лет назад

The daemon in GDM through 3.29.1 does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local attacker to trigger a use-after-free via a specially crafted sequence of D-Bus method calls, resulting in a denial of service or potential code execution.

CVSS3: 7.3
redhat
больше 7 лет назад

The daemon in GDM through 3.29.1 does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local attacker to trigger a use-after-free via a specially crafted sequence of D-Bus method calls, resulting in a denial of service or potential code execution.

CVSS3: 7.8
debian
больше 7 лет назад

The daemon in GDM through 3.29.1 does not properly unexport display ob ...

suse-cvrf
больше 7 лет назад

Security update for gdm

suse-cvrf
больше 7 лет назад

Security update for gdm

EPSS

Процентиль: 22%
0.00074
Низкий

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-416