Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2017-12164

Published: 26 July 2018

A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin. If autologin was enabled for a victim, an attacker could simply select 'login as another user' to unlock their screen.

Notes

AuthorNote
leosilva
according with RHEL it's a side effect introduced in gdm-3.24.1
affecting only artful and zesty.
mdeslaur
introduced by ff98b2817014684ae1acec78ff06f0f461a56a9f

Priority

Medium

Cvss 3 Severity Score

6.4

Score breakdown

Status

Package Release Status
gdm3
Launchpad, Ubuntu, Debian
artful
Released (3.26.0-1ubuntu1)
trusty Does not exist

upstream Needs triage

xenial Not vulnerable
(code not present)
zesty
Released (3.24.1-0ubuntu0.2)
Patches:
upstream: https://git.gnome.org/browse/gdm/commit/?id=798be427d2cf9bd2cdcffb75cacc3ab7fd1b1234

Severity score breakdown

Parameter Value
Base score 6.4
Attack vector Physical
Attack complexity High
Privileges required None
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H