6.8
CVSSv2

CVE-2007-4569

Published: 21/09/2007 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 10 | Exploitability Score: 3.1
VMScore: 605
Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

backend/session.c in KDM in KDE 3.3.0 up to and including 3.5.7, when autologin is configured and "shutdown with password" is enabled, allows remote malicious users to bypass the password requirement and login to arbitrary accounts via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

kde kde 3.4.0

kde kde 3.4.1

kde kde 3.5.3

kde kde 3.5.4

kde kde 3.3.1

kde kde 3.3.2

kde kde 3.4

kde kde 3.5.1

kde kde 3.5.2

kde kde 3.4.2

kde kde 3.4.3

kde kde 3.5.5

kde kde 3.5.6

kde kde 3.3

kde kde 3.3.0

kde kde 3.5

kde kde 3.5.0

kde kde 3.5.7

Vendor Advisories

It was discovered that KDM would allow logins without password checks under certain circumstances If autologin was configured, and “shutdown with password” enabled, a local user could exploit the problem and gain root privileges ...
iKees Huijgen discovered that under certain circumstances KDM, an X session manager for KDE, could be tricked into allowing user logins without a password For the old stable distribution (sarge), this problem was not present For the stable distribution (etch), this problem has been fixed in version 4:355adfsg1-6etch1 We recommend that you up ...