7.8
CVSSv3

CVE-2015-8308

Published: 24/08/2017 Updated: 30/08/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

LXDM prior to 0.5.2 did not start X server with -auth, which allows local users to bypass authentication with X connections.

Vulnerable Product Search on Vulmon Subscribe to Product

lxdm project lxdm

Vendor Advisories

Debian Bug report logs - #805659 lxdm: CVE-2015-8308: X server started without -auth, exposing it to connections form any local user Package: src:lxdm; Maintainer for src:lxdm is Debian LXDE Maintainers <pkg-lxde-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 20 ...