Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-14424

Опубликовано: 13 авг. 2018
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

The daemon in GDM through 3.29.1 does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local attacker to trigger a use-after-free via a specially crafted sequence of D-Bus method calls, resulting in a denial of service or potential code execution.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gdmNot affected
Red Hat Enterprise Linux 7gdmWill not fix
Red Hat Enterprise Linux 8gdmNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1606915gdm: use-after-free in the GDM daemon

EPSS

Процентиль: 22%
0.00074
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 7 лет назад

The daemon in GDM through 3.29.1 does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local attacker to trigger a use-after-free via a specially crafted sequence of D-Bus method calls, resulting in a denial of service or potential code execution.

CVSS3: 7.8
nvd
больше 7 лет назад

The daemon in GDM through 3.29.1 does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local attacker to trigger a use-after-free via a specially crafted sequence of D-Bus method calls, resulting in a denial of service or potential code execution.

CVSS3: 7.8
debian
больше 7 лет назад

The daemon in GDM through 3.29.1 does not properly unexport display ob ...

suse-cvrf
больше 7 лет назад

Security update for gdm

suse-cvrf
больше 7 лет назад

Security update for gdm

EPSS

Процентиль: 22%
0.00074
Низкий

7.3 High

CVSS3