← Back

CVE-2019-3825

nvd nist
Published: Feb 6, 2019Modified: Nov 21, 2024

JSON object

Loading...
6.4
Vector
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.5 / Impact: 5.9
Source: NVD

Description

A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could bypass the lock screen by selecting the timed login user and waiting for the timer to expire, at which time they would gain access to the logged-in user's session.

Affected (4)

1 product
Gnome Display Manager
1 product
Ubuntu Linux
1 product
Enterprise Linux
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.31.4
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 18.04
Version 18.10
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.0

References (4)

Source: secalert@redhat.com
ExploitIssue TrackingMitigationThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.