CVE-2019-3825
6.4
Vector
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.5 / Impact: 5.9
Source: NVD
Description
A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could bypass the lock screen by selecting the timed login user and waiting for the timer to expire, at which time they would gain access to the logged-in user's session.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.31.4 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 18.04 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.0 |
References (4)
Source: secalert@redhat.com
ExploitIssue TrackingMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingMitigationThird Party Advisory
Timeline
No history available yet.