6.4
CVSSv3

CVE-2019-3825

Published: 06/02/2019 Updated: 09/10/2019
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
CVSS v3 Base Score: 6.4 | Impact Score: 5.9 | Exploitability Score: 0.5
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

A vulnerability exists in gdm prior to 3.31.4. When timed login is enabled in configuration, an attacker could bypass the lock screen by selecting the timed login user and waiting for the timer to expire, at which time they would gain access to the logged-in user's session.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnome gnome display manager

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

redhat enterprise linux 7.0

Vendor Advisories

Debian Bug report logs - #921764 CVE-2019-3825 Package: src:gdm3; Maintainer for src:gdm3 is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Fri, 8 Feb 2019 21:33:02 UTC Severity: important Tags: upstream Found in version gdm3/3302-2 ...
GDM could give unauthorized access to a different user ...
Synopsis Moderate: GNOME security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for GNOME is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System ...
Synopsis Important: Container-native Virtualization security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Virtualization release 240 is now available with updates to packages and images that fix several bugs and add enhancementsRed Hat Product Securi ...
Synopsis Moderate: OpenShift Container Platform 461 image security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat OpenShift Container Platform 46Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability S ...
A vulnerability was discovered in gdm before 3314 When timed login is enabled in configuration, an attacker could bypass the lock screen by selecting the timed login user and waiting for the timer to expire, at which time they would gain access to the logged-in user's session ...
An issue has been found in gdm <= 3302, allowing a local attacker with valid credentials to unlock the session for a different user than their own ...