Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-27837

Опубликовано: 28 дек. 2020
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.4
CVSS3: 6.4

Описание

A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it possible to bypass the lock screen for a user that has autologin enabled, accessing their session without authentication. This is similar to CVE-2017-12164, but requires more difficult conditions to exploit.

РелизСтатусПримечание
bionic

not-affected

devel

not-affected

43.0-1ubuntu1
esm-apps/xenial

not-affected

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

esm-infra/focal

needed

focal

ignored

end of standard support, was needed
groovy

ignored

end of life
hirsute

ignored

end of life
impish

ignored

end of life

Показывать по

Ссылки на источники

EPSS

Процентиль: 12%
0.00041
Низкий

4.4 Medium

CVSS2

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.3
redhat
около 5 лет назад

A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it possible to bypass the lock screen for a user that has autologin enabled, accessing their session without authentication. This is similar to CVE-2017-12164, but requires more difficult conditions to exploit.

CVSS3: 6.4
nvd
около 5 лет назад

A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it possible to bypass the lock screen for a user that has autologin enabled, accessing their session without authentication. This is similar to CVE-2017-12164, but requires more difficult conditions to exploit.

CVSS3: 6.4
debian
около 5 лет назад

A flaw was found in GDM in versions prior to 3.38.2.1. A race conditio ...

github
больше 3 лет назад

A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it possible to bypass the lock screen for a user that has autologin enabled, accessing their session without authentication. This is similar to CVE-2017-12164, but requires more difficult conditions to exploit.

EPSS

Процентиль: 12%
0.00041
Низкий

4.4 Medium

CVSS2

6.4 Medium

CVSS3