Description
gdm3 versions before 3.36.2 or 3.38.2 would start gnome-initial-setup if gdm3 can't contact the accountservice service via dbus in a timely manner; on Ubuntu (and potentially derivatives) this could be be chained with an additional issue that could allow a local user to create a new privileged account.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2434-1 | gdm3 security update |
Ubuntu USN |
USN-4614-1 | GDM vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2024-09-17T03:59:24.216Z
Reserved: 2020-07-29T00:00:00.000Z
Link: CVE-2020-16125
No data.
Status : Modified
Published: 2020-11-10T05:15:11.893
Modified: 2024-11-21T05:06:48.720
Link: CVE-2020-16125
OpenCVE Enrichment
No data.
Debian DLA
Ubuntu USN